ROBOT vulnerability mitigation?
I have a 100D running 5.4.8 with an HTTPS type virtual server VIP, and https://www.ssllabs.com/ssltest/analyze.html is marking the site in question as vulnerable to ROBOT (Return of Bleichenbacher's Oracle Threat) attack. The VIP settings are currently set as follows:
set ssl-mode full set ssl-dh-bits 2048 set ssl-algorithm high set ssl-server-algorithm client set ssl-pfs allow set ssl-min-version tls-1.0 set ssl-max-version tls-1.2 set ssl-server-min-version client set ssl-server-max-version client set ssl-send-empty-frags enable set ssl-client-fallback enable set ssl-client-renegotiation secure set ssl-client-session-state-type both set ssl-client-session-state-timeout 30 set ssl-client-session-state-max 1000 set ssl-server-session-state-type both set ssl-server-session-state-timeout 60 set ssl-server-session-state-max 100
Fortinet's official advisory is that FortiOS is not affected ( https://fortiguard.com/psirt/FG-IR-17-302%20 ) - is this a false positive on the part of SSLLabs, or is it true, and if yes, what can be done to mitigate it?