Skip to main content
dkochhar
Staff
Staff
March 19, 2025

Troubleshooting Tip: FSSO status down due to poor key strength

  • March 19, 2025
  • 0 replies
  • 370 views
Description This article describes an issue where the status of the FSSO secure connection appears as down due to poor key strength.
Scope FortiGate.
Solution The FSSO secure connection is displayed as down.

FSSO-1.png

 

In the Packet Captures, the FortiGate has sent 'Alert (Level: Fatal, Description: Bad Certificate)'.

This alert message is triggered when FortiGate is unable to validate the server certificate presented by the Collector agent.

 

FSSO.png

 
Ensure that the certificate's key strength is not too low. The certificate used for establishing the FSSO SSL connection should have a minimum key strength of 2048 bits.

 

FSSO-2.png