Skip to main content
odahy
Staff
Staff
November 21, 2024

Technical Tip : Allowed ECC Certificates under FIPS mode

  • November 21, 2024
  • 0 replies
  • 821 views
Description This article describes the allowed types of ECC Certificates when enabling FIPS on FortiGate.
Scope FortiOS.
Solution

When FIPS mode is enabled in the FortiOS some already imported  ECC (Elliptical curve cryptography) certificates might not work as intended.

As the FortiGate under this mode will only allow ECC certificates using ECDSA Elliptic curves, a digital signature algorithm using NIST curves will be as follows: (P192, P-224, P-256, P-384 and P-521).

 

More regarding the approved ECDSA approved curves can be read in NIST.FIPS.186-4.
See the image below for an example of an unapproved ECDSA Certificate using brainpool curves instead of NIST curves:

Screenshot 2024-11-21 104357.png

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!