TLS/SSL handshake logs with Certificate Inspection profile
Hi everyone,
I’m trying to understand whether there is a way to log some TLS/SSL handshake information when using an SSL/SSH profile configured with Certificate Inspection, rather than Full/Deep Inspection.
I tested the following settings:
set ssl-handshake-log enable
set ssl-server-cert-log enable
set ssl-negotiation-log enablebut, from my tests, these logs seem to be generated only when the SSL/SSH profile is configured for Full/Deep Inspection.
What I would specifically like to retrieve, even when using Certificate Inspection, is information such as:
- the SNI (Server Name Indication) sent by the client;
- the negotiated TLS version;
- ideally, other basic TLS handshake metadata that FortiGate can observe without decrypting the session.
Since SNI and TLS version are available during the handshake and do not necessarily require payload decryption, it would be very useful to have them available in the traffic/SSL logs also with Certificate Inspection.
Thanks in advance for any suggestions or clarification.
Â
