How to Fix SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED in Firefox (Pakistan Guide)

Resolve SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED errors in Firefox. Fix deprecated SHA-1, legacy MD5 certificates, OpenSSL re-issuance, and NSS security policy blocks in Pakistan.

How to Fix SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED in Firefox (Pakistan Guide)

When attempting to access internal enterprise portals, local bank administration panels, legacy network firewalls, or self-hosted cPanel instances in Pakistan, Mozilla Firefox may abruptly halt your connection with an alarming warning screen:

An error occurred during a connection to portal.company.pk.
Peer’s Certificate has been rejected as having an invalid signature algorithm.
Error code: SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED

Unlike ordinary certificate expiration errors that allow you to click “Accept the Risk and Continue,” Firefox’s Network Security Services (NSS) cryptography engine considers insecure signature algorithms an existential transport-layer threat. In this technical deep dive, we examine why NSS blocks these certificates, how to inspect cryptographic headers, and the step-by-step procedures to reissue compliant SSL/TLS certificates.


1. Cryptographic Anatomy of the Error

Mozilla Firefox adheres strictly to the CA/Browser Forum Baseline Requirements. The error code SEC_ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED is triggered when the digital signature on the server’s X.509 certificate—or any intermediate certificate in the trust chain—was computed using a cryptographic hash algorithm that has been cryptographically deprecated or broken.

Deprecated vs Modern Signature Algorithms

Signature Algorithm OID Identifier Security Status Firefox NSS Behavior
md5WithRSAEncryption 1.2.840.113549.1.1.4 Compromised (Collisions proven) Blocked unconditionally
sha1WithRSAEncryption 1.2.840.113549.1.1.5 Deprecated (SHAttered attack) Blocked for all public WebPKI certs
sha256WithRSAEncryption 1.2.840.113549.1.1.11 Secure Standard Fully Supported
sha384WithRSAEncryption 1.2.840.113549.1.1.12 High-Assurance Enterprise Fully Supported
ecdsa-with-SHA256 1.2.840.10045.4.3.2 Modern Elliptic Curve (P-256) Recommended (Sub-millisecond)

In Pakistan, many enterprise web hosts and legacy ERP systems deploy legacy appliance certificates or older internal CAs generated before 2017 that still rely on SHA-1 hashing.

For mission-critical production infrastructure requiring modern TLS 1.3 cryptographic offloading, deploying modern hardware with hardware crypto acceleration is essential. See how our Dedicated Servers and localized Dedicated Servers in Pakistan support line-rate hardware-accelerated TLS.


2. Inspecting the Offending Certificate Chain via CLI

Before modifying web server configurations or client browsers, verify the exact certificate in the chain causing the signature violation using OpenSSL:

# Query the target server and extract the leaf signature algorithm
openssl s_client -connect portal.company.pk:443 -servername portal.company.pk -showcerts </dev/null 2>/dev/null | openssl x509 -noout -text | grep -E "(Signature Algorithm|Public Key Algorithm|Issuer)"

Typical Failing Output:

    Signature Algorithm: sha1WithRSAEncryption
        Issuer: CN=Old Enterprise Local CA, O=Company PK, C=PK
        Subject: CN=portal.company.pk
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (2048 bit)
    Signature Algorithm: sha1WithRSAEncryption

Notice sha1WithRSAEncryption. Firefox detects this weak hash and refuses to construct a validated certification path.


3. Server-Side Remediation: Re-issuing SHA-256 or ECDSA Certificates

The definitive, permanent fix is replacing the weak certificate with a certificate signed using SHA-256 or Elliptic Curve Cryptography.

Option A: Generating a Modern SHA-256 RSA Certificate

# Generate private key and CSR with SHA-256 signature
openssl req -new -newkey rsa:2048 -nodes -keyout /etc/ssl/private/portal.key \
    -sha256 \
    -out /etc/ssl/certs/portal.csr \
    -subj "/C=PK/ST=Sindh/L=Karachi/O=Enterprise Ltd/CN=portal.company.pk"

# Self-sign with explicit SHA-256 (if using internal CA/self-signed testing)
openssl x509 -req -days 365 -in /etc/ssl/certs/portal.csr \
    -signkey /etc/ssl/private/portal.key \
    -sha256 \
    -out /etc/ssl/certs/portal.crt

Option B: Generating an Ultra-Fast ECC Certificate (P-256 / SHA-256)

# Generate EC private key using prime256v1 curve
openssl ecparam -name prime256v1 -genkey -noout -out /etc/ssl/private/portal_ecc.key

# Generate CSR and certificate with ecdsa-with-SHA256
openssl req -new -key /etc/ssl/private/portal_ecc.key \
    -sha256 \
    -out /etc/ssl/certs/portal_ecc.csr \
    -subj "/C=PK/ST=Punjab/L=Lahore/O=Fintech Hub/CN=portal.company.pk"

openssl x509 -req -days 365 -in /etc/ssl/certs/portal_ecc.csr \
    -signkey /etc/ssl/private/portal_ecc.key \
    -sha256 \
    -out /etc/ssl/certs/portal_ecc.crt

Option C: Automating with Let’s Encrypt (Certbot on Nginx/Apache)

If the server is publicly accessible across Pakistan, use Certbot to automatically fetch compliant certificates:

# Install and run Certbot with ECDSA default key type
certbot --nginx -d portal.company.pk --key-type ecdsa

4. Emergency Workaround for Legacy Internal Appliances (Client-Side)

If the target system is an unupgradable legacy hardware appliance (e.g., an outdated router or SAN controller) located inside a secure private LAN, you can temporarily adjust Firefox’s SHA-1 enforcement level.

[!WARNING] Do NOT use this workaround for public browsing. Changing this policy exposes your browser to counterfeit SSL certificates if a threat actor computes SHA-1 collision preimages.

  1. Open a new tab in Firefox and navigate to about:config.
  2. Accept the warning prompt: “Accept the Risk and Continue”.
  3. Search for the preference:
    security.pki.sha1_enforcement_level
  4. By default, this value is set to 1 (strict enforcement).
  5. Double-click to edit and change the integer to:
    • 0: Allows SHA-1 certificates globally for all trust chains.
    • 2: Allows SHA-1 certificates issued by locally imported Root CAs only.
  6. Restart Firefox and access the legacy management console. Revert this setting back to 1 once administrative tasks are complete.

5. Verifying the Intermediate Certificate Chain

Frequently, the leaf certificate uses sha256WithRSAEncryption, but the intermediate certificate issued by an older enterprise root CA still utilizes SHA-1.

Check the complete chain using OpenSSL:

openssl s_client -connect portal.company.pk:443 -showcerts | grep -E "s:|i:|Signature Algorithm"

If an intermediate certificate displays SHA-1, update the certificate bundle (fullchain.pem or ca-bundle.crt) on the server with the modern SHA-256 intermediate issued by the Certificate Authority.

For related browser security diagnostics and certificate chain validation, explore our tutorials on How to fix SEC_ERROR_CA_CERT_INVALID in Firefox and How to fix SSL_ERROR_NO_CYPHER_OVERLAP. If you run complex microservice clusters, review our dedicated Cloud VPS hosting options.


HARDENED ENTERPRISE INFRASTRUCTURE

Deploy Secure, High-Performance Dedicated Servers

Protect your mission-critical applications with ISO-compliant security, automated Let's Encrypt SSL orchestration, and enterprise hardware firewalls in Pakistani Tier-3 datacenters.