Remediating security vulnerabilities
Very new to Fortinet products, so please bear with me.
I'm a government contractor and we've got a few FortiGate 200Ds (firmware version 5.2.9) and a FortiManager 1000D (firmware version 5.2.8) for a project we're still in the process of standing up. As part of this we're using AlienVault to scan hosts for security vulnerabilities and I got reports about our FortiGates and the FortiManager. I've managed to fix all the high priority vulnerabilities on the FortiGates except for one medium, which I think can be resolved with a new certificate that doesn't use the SHA-1 signature algorithm. Most of the fixes were readily available online, and I'm fairly confident I can fix the last one once I get around to it. But the FortiManager is proving to be a giant pain.
I was able to resolve one of the three high findings regarding SSL weak ciphers, which removed 10 ciphers from the list available by telling FortiManager to set enc-algorithm to high. Unfortunately there are 6 weak ciphers still detected:
TLS1_RSA_RC4_128_MD5 TLS1_RSA_RC4_128_MD5 TLS_1_2_RSA_WITH_RC4_128_MD5 TLS_1_2_RSA_WITH_3DES_EDE_CBC_SHATLS_1_2_DHE_RSA_WITH_3DES_EDE_CBC_SHA TLS_1_2_RSA_WITH_3DES_EDE_CBC_SHA I've got a month to fix these high severity findings, but none of the documentation I've read or found online has been a lot of help in finding the solution. In addition to the 2 high severity findings there are also 2 medium severity findings regarding the Diffie-Hellman group using a 1024-bit key instead of the recommended 2048-bit, 2 medium severity findings regarding the SHA-1 weak signature algorithm, and 1 medium severity finding regarding FortiManager implementing time stamps. My google-fu is failing me for now, so if anyone can point me in the right direction I would be really grateful.
