Skip to main content

Signature algorithms

The signature algorithm defines the hash and signature algorithms the issuing CA certificate (Intermediate CA or Root CA) can use to sign a certificate request. You must specify a default signature algorithm from the list of allowed algorithms in case the certificate request does not specify what signature algorithm should be used.

JSON structure example

"signature_algorithm": {
  "allowed_algorithms": [
    "sha1WithRSA",
    "sha256WithRSA",
    "sha384WithRSA",
    "sha512WithRSA",
    "sha256WithECDSA",
    "sha384WithECDSA",
    "sha512WithECDSA",
    "sha3_256WithRSA",
    "sha3_384WithRSA",
    "sha3_512WithRSA",
    "pureEd25519",
    "hashedEd25519",
    "daimlerHashedEd25519",
    "MLDSA-44",
    "MLDSA-65",
    "MLDSA-87",
    "SLHDSA-SHA2-128f",
    "SLHDSA-SHA2-128s",
    "SLHDSA-SHA2-192f",
    "SLHDSA-SHA2-192s",
    "SLHDSA-SHA2-256f",
    "SLHDSA-SHA2-256s",
    "SLHDSA-SHAKE-128f",
    "SLHDSA-SHAKE-128s",
    "SLHDSA-SHAKE-192f",
    "SLHDSA-SHAKE-192s",
    "SLHDSA-SHAKE-256f",
    "SLHDSA-SHAKE-256s",
    "FNDSA-512",
    "FNDSA-1024",
    "match_issuer"
  ],
  "default_algorithm": "match_issuer"
}Some code

Parameters

tabel 1. Parameters - Signature algorithms

Name

Type

Required/optional

Possible values

allowed_algorithms

Array of string

Required

RSA algorithms:

  • sha1WithRSA

  • sha256WithRSA

  • sha384WithRSA

  • sha512WithRSA

ECDSA Algorithms:

  • sha256WithECDSA

  • sha384WithECDSA

  • sha512WithECDSA

SHA-3 algorithms:

  • sha3_256WithRSA

  • sha3_384WithRSA

  • sha3_512WithRSA

Ed25519 algorithms:

  • pureEd25519

  • hashedEd25519

  • daimlerHashedEd25519

MLDSA algorithms:

  • MLDSA-44

  • MLDSA-65

  • MLDSA-87

SLHDSA algorithms:

  • SLHDSA-SHA2-128f

  • SLHDSA-SHA2-128s

  • SLHDSA-SHA2-192f

  • SLHDSA-SHA2-192s

  • SLHDSA-SHA2-256f

  • SLHDSA-SHA2-256s

  • SLHDSA-SHAKE-128f

  • SLHDSA-SHAKE-128s

  • SLHDSA-SHAKE-192f

  • SLHDSA-SHAKE-192s

  • SLHDSA-SHAKE-256f

  • SLHDSA-SHAKE-256s

FNDSA algorithms:

  • FNDSA-512

  • FNDSA-1024

Others:

match_issuer

default_algorithm

string

Required

An algorithm from the list of allowed_algorithms