What is a hash function?
A cryptographic hash function turns any input, from one letter to a multi-gigabyte file, into a short fixed-length fingerprint called a digest. The same input always gives the same digest, and changing a single bit changes about half of the output bits, the avalanche effect. SHA-256 always produces 256 bits, written as 64 hexadecimal characters; MD5 gives 32 characters, SHA-1 40, SHA-384 96 and SHA-512 128.
A secure hash has three properties. Preimage resistance: given a digest, you cannot find an input that produces it. Second-preimage resistance: given one input, you cannot find another with the same digest. Collision resistance: you cannot find any two inputs with the same digest. When the last property breaks, the hash is no longer safe for signatures or certificates.