Skip to main content
TIBarigui
New Member
February 20, 2017
Question

FortiOS and SHA256

  • February 20, 2017
  • 10 replies
  • 20214 views

Hello!

 

Has anyone found any documentation on Fortigate's documentation sying anithing about compatibilities between Fortigate and SHA256? We have a 240D Fortigate in 5.2.3 version.

 

With the deprecation of sha1 certificates, I'm now having problems with my Deep Inspection. Strange thing that even using an sha256 certificate, the Fortigate presents a sha1 certificate to the browser.

 

I opened a ticket with the support and they said FortiOs is compatible with sha256 since v5.2.6, bur I couldn't find any mention to that in documentation from 5.2.6 to 5.2.8.

 

Any hints?

 

Thanks

    10 replies

    MikePruett
    New Member
    February 20, 2017

    Are you pushing a Sha256 cert to the Gate and then using that as your inspection cert?

     

    Also, you probably want to push your firmware up to the 5.2.10 range (using proper upgrade path of course). There are some security bugs in 5.2.3 you will want to mitigate.

    TIBarigui
    TIBariguiAuthor
    New Member
    February 20, 2017

    Mike,

     

    Thanks for your response.

     

    You're right, I'm using a sha256 cert from my internal CA to use as my inspection cert.

     

    TAC told me that I should upgrade my OS from at least 5.2.6.. I was wondering if that is true because there is no note about this matter in the changelog.

     

    I'll try the upgrade and then I inform the results.

    mattnotley2004
    New Member
    February 21, 2017

    TIBarigui wrote:

    Mike,

     

    Thanks for your response.

     

    You're right, I'm using a sha256 cert from my internal CA to use as my inspection cert.

     

    TAC told me that I should upgrade my OS from at least 5.2.6.. I was wondering if that is true because there is no note about this matter in the changelog.

     

    I'll try the upgrade and then I inform the results.

    We are having deep inspection issues too since the deprecation of SHA1. Has only started to hit us recently on a small group of Chromebooks running Chrome OS Beta (v57), which are displaying "Weak Signature Algorithm" warnings on all HTTPS sites using the newer certificates (not just Google sites). Production devices running Chrome OS 56 and lower are fine.

     

    If the upgrades resolves your deep inspection problem, we will follow suit.

    bommi
    New Member
    February 20, 2017

    TIBarigui wrote:

    Hello!

     

    Has anyone found any documentation on Fortigate's documentation sying anithing about compatibilities between Fortigate and SHA256? We have a 240D Fortigate in 5.2.3 version.

     

    With the deprecation of sha1 certificates, I'm now having problems with my Deep Inspection. Strange thing that even using an sha256 certificate, the Fortigate presents a sha1 certificate to the browser.

     

    I opened a ticket with the support and they said FortiOs is compatible with sha256 since v5.2.6, bur I couldn't find any mention to that in documentation from 5.2.6 to 5.2.8.

     

    Any hints?

     

    Thanks

    Hello!

     

    at least with FortiOS 5.6 Beta2 my fortigate signs all certificates using sha256.

     

    Regards

    bommi

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!