Skip to main content
phil_rose
Staff
Staff
October 25, 2024

Technical Tip: Best Practices for Maintaining Secure Credentials

  • October 25, 2024
  • 0 replies
  • 5527 views
Description

This article describes and itemizes key credentials to maintain in order to assure strong security best practices.

Administrators are advised to periodically refresh these credentials, in addition to giving particular attention in any event where an organization may need to give heightened attention to security. It is strongly suggested to avoid repeat usage and establish unique credentials per instance to all practical extents possible.

Scope

FortiGate

Solution

Update the following security credentials:

  • Admin Users Accounts
  • Certificate’ s private key and password (In case of ssl offloading/deep inspection/ipsec auth)
  • VPN Pre-Shared Keys
  • Local user accounts
  • TACACS Key
  • LDAP / Active Directory Passwords
  • RADIUS Secret Keys
  • SNMP v2 community string
  • SNMP v3 auth/priv password
  • DDNS password
  • OSPF/BGP Neighbour Passwords
  • Wireless SSID / Mesh Keys
  • Passwords stored inside automation stitches
  • PPPoE Passwords
  • SMTP Passwords
  • HA Pre-shared Keys Cluster Password