Skip to main content
Ydaew
New Member
July 16, 2019
Solved

SSL Decription

  • July 16, 2019
  • 1 reply
  • 2509 views

Hello, 

I'm using FortiGate to decrypt web server traffic, how to know if the traffic is really decrypted from the FortiGate log itself ?

    Best answer by emnoc

    You can monitor the logs and look at that fwpolicyid. A sure way is to inspect the client\server-hello. If you see the MiTM  forced certificate in the https lock in the browser, than you know a device was in the middle. Review the following 

     

    http://socpuppet.blogspot.com/2017/11/ssl-state-cache-msie.html

     

    The left screenshot is a proxy doing MiTM and the right is the correct ca-chain. https://crt.sh/ is a good tool to know the proper cert issuer details btw.

     

    e.g ( to see all cert listed for example.com ) 

     

    https://crt.sh/?q=%25.example.com

     

    Ken Felix

    1 reply

    emnoc
    emnocAnswer
    New Member
    July 16, 2019

    You can monitor the logs and look at that fwpolicyid. A sure way is to inspect the client\server-hello. If you see the MiTM  forced certificate in the https lock in the browser, than you know a device was in the middle. Review the following 

     

    http://socpuppet.blogspot.com/2017/11/ssl-state-cache-msie.html

     

    The left screenshot is a proxy doing MiTM and the right is the correct ca-chain. https://crt.sh/ is a good tool to know the proper cert issuer details btw.

     

    e.g ( to see all cert listed for example.com ) 

     

    https://crt.sh/?q=%25.example.com

     

    Ken Felix

    Thought Leadership. Security Summit. Thursday, November 12th, PGA National Resort, Palm Beach Gardens, FL.
    Thought Leadership. Security Summit. Thursday, October 8th. Disney's Grand Californian Hotel & SPA, Anaheim, CA.
    Security Operations Summit: Modernize SecOps. Operate AI-Native.AMER: November 4 | 9:00 AM PST. India and SAARC: November 5 | 10:00 AM IST. EMEA: November 5 | 10:30 AM CET. APAC: November 5 | 11:00 AM SGT