Skip to main content
Cyriel
New Member
July 28, 2015
Question

[deep-scanning] Import Firefox root-CA list

  • July 28, 2015
  • 1 reply
  • 2594 views

Hello,

 

I try to export all firefox root-ca for import to the Fortigate Unit.

Do you have any idea for the best solution ?

 

The goal is activate this option for control if the CA Certificate is signed by trusted CA.

config firewall ssl-ssh-profile
edit deep-inspection
config https
set allow-invalid-server-cert disable
set ssl-ca-list enable
end
end

 

Thank you for your help.

    1 reply

    Cyriel
    CyrielAuthor
    New Member
    August 2, 2015

    I found the perl script mk-ca-bundle that I adapted for Fortigate.

    You can find it here : http://git.noweak.fr/cyriel/mk-ca-bundle-pl/blob/master/mk-ca-bundle.pl

     

    Usage : ./mk-ca-bundle.pl -v -d release -p ALL:ALL