Skip to main content
vdaam
New Member
March 12, 2024
Question

SSL Inspection and FIPS mode 7.2.X

  • March 12, 2024
  • 1 reply
  • 1340 views

Is anyone out there successfully running full SSL inspection and also has FIPS-CC enabled? I should mention also that the policy needs to be in Proxy mode NOT flow.

I recently ran into an issue where once I put the policy into proxy mode all new sessions start failing.

After working with support we found that the WAD proxy module is referencing this private key " Fortinet_SSL_RSA1024.key ". FIPS modes does not allow keys below 2048 so obviously this key is not there and its failing https://omegle.onl/ .

SSL inspection still works in flow mode but I know its recommended when using DPI to use proxy based inspection.

Just curious if anyone else has ran into this. Seems like SSL inspection is something that if you are in FIPS mode you would most likely be using.

Thanks

1 reply

Jackie_T
Staff & Editor
Staff & Editor
March 13, 2024

Hi Vdaam,

 

If you do a list of the local certificates >> "show vpn certificate local | grep edit" , do you see the Fortinet_SSL_RSA1024 certificate listed there?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.