Checks

Certificate uses a weak signature

The certificate is signed with a weak hash, such as SHA-1 or MD5.

Why it matters

A weak signature hash can let an attacker forge a certificate that chains to the same issuer.

What to do

Reissue using SHA-256 or stronger.

Reference

Certificate validity, protocol version, and cipher choice determine TLS trust and strength.

Mozilla SSL Configuration Generator