Skip to main content
Christian_Bootz
New Member
July 13, 2011
Question

extract preshared key from config file

  • July 13, 2011
  • 2 replies
  • 5716 views
Dear fortinet specialists, does anybody know how to extract an encrypted preshared key from config file? The psk in our environment isn' t anywhere to be found. To avoid a completely new ipsec configuration on all devices it would be better to get the key via config file. However, the FortiClient VPN Tool creates a config file with an encryped psk inside. The same happens by saving config of the FG device. Up to now it was possible to use the FortiClient config files to get new Windows devices working. Now there' s in iPad i want to get working and so i have to enter all config data manually. Regards, Christian

    2 replies

    Jan_Scholten
    New Member
    July 13, 2011
    hopefully the psks are save in the config files.. -> no i don' t know any way and i hope this stays that way.. imagine everyone could extract your keys out of the profiles/configs..
    Christian_Bootz
    New Member
    July 14, 2011
    OK, I think the psks are safe in the config files. It seems there is used md5 or sha1 to generate a checksum of the psk, usernames and also passwords and so it should be impossible to recreate readable phrases. However, there is a well known way to decrypt psks in config files saved by Cisco vpn client: http://coreygilmore.com/projects/decrypt-cisco-vpn-password/ So I thought there could be a similar way for FortiClient. Regards, Christian
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!