Question
TLS Session Renegotiation vulnerability
Anybody know if its possible to turn off SSL/TLS session renegotiation in a Fortigate 50B or if there is a firmware that includes the new renegotiation protocol that isn' t vulnerable to a MITM attack? My PCI vulnerability scan found this vulnerability on my SSL VPN port but I imagine its also there if you use remote administration. I tested it using some other tools as well and its definitely using the vulnerable protocol. Cn' t find anything in the CLI manual on how to turn off renegotiation. I' ve opened a ticket but it looks like support is seriously backlogged and it hasn' t been assigned to anyone for 3 business days now. This vulnerability has been around for over 6 months now with a lot of press so I' m surprised I couldn' t find anything in the knowledgebase or here on the forum about a mitigation or fix for the Fortigates.
