You get all SHA1 certificates listed in event viewer.
Source: CertDependancyTracker
Category: Certificate Compliance
The problem with this requirement is, when you use AP factory default certificate for DOT1X to authenticate APs, older APs (series 3xx and older, maybe some of 5xx - didn't check it yet) has certificates signed by SHA1 CA certificates. Authentication will fail for these APs. Currently the only solution I see is to deploy local certificate to APs before starting upgrade to 6.14.
Best, Gorazd
------------------------------
Gorazd Kikelj
MVP Guru 2025
------------------------------
Original Message:
Sent: Jul 05, 2026 09:59 PM
From: BF-CPm358
Subject: Issue with upgrade from CPPM 6.12 to 6.14
New issue - upgrade to 6.14 wants all SHA1 certs removed! The only way to know which certs are SHA1 signed is to click and inspect each certificate one by one. Even from a brand new 6.12 install there are dozens of SHA1 trust certs added that will now have to be removed.
And another - after the update failed and the error was cleared the image has vanished and has to be downloaded (4GB) again.
Last attempt corrupted GRUB and now the VM is dead. Luckily it was only a new node not in production
Original Message:
Sent: Jun 12, 2026 01:08 AM
From: BF-CPm358
Subject: Issue with upgrade from CPPM 6.12 to 6.14
Release Notes:
"Starting with the 6.14.0 release, underscores are not allowed in hostnames. Upgrades from 6.11.x or 6.12.x to 6.14.0 are blocked if the hostname includes an underscore. The only characters allowed in hostnames are numbers, uppercase letters, and lowercase letters. (CP‑57077)"
What about dashes?? I'm using those now in our hostname just fine.