Technical Tip: Blocking clients that are not compliant with RFC 9155
Description | This article describes how to make FortiADC stop TLS handshakes with clients that are sending MD5 or SHA-1 in the signature_algorithms extension in the TLS handshake as per the RFC 9155 requirements. |
Solution | FortiADC version 8.0.3 and above. |
Solution | Modify the client SSL profile using the CLI to state the allowed signature algorithms and be sure not to include SHA-1 or MD5.
|
