SHA-2 as default, multi-year options reduced, internal domains
1. Changeover from SHA-1 to SHA-2
The previously used Secure Hash Algorithmus SHA-1 is not regarded as totally secure anymore. Google and Microsoft decided to reject SSL certificates using SHA-1 in the future and to denote them in their browsers as „not secure". All websites with SSL certificates expiring after December 31, 2015 and using SHA-1 are affected by this devaluation. To avoid that these derogatory indicators are shown to online users with e.g. Chrome version 39, SHA-1 SSL certificates expiring after December 31, 2015, should be substituted by SHA-256 (SHA-2)-certificates.
As of November 3, 2014 all new SSL certificates from Symantec, thawte, GeoTrust and RapidSSL issued by CentralNic Reseller will therefore by default be signed with algorithm SHA-2, which is regarded as more secure. Comodo products are already signed with SHA-2. For already issued certificates the changeover from SHA-1 to SHA-2 can be enforced by using the parameter "ALGORITHM = SHA2-256" in the command ReissueCertificate.The reissuing of the certificate is not associated with any costs. If you want to maintain SHA-1 for new certificates, you can restore the default setting with the parameter "ALGORITHM = SHA1".