Created on
10-16-2024
02:42 AM
Edited on
10-16-2024
02:44 AM
By
Jean-Philippe_P
| Description |
This article describes why FortiADC will not allow enabling RFC 7919 Comply when SSLv3 or TLSv1.3 is selected in Allowed SSL Version in Client SSL profiles and will generate an error stating 'Client SSL RFC7919 Comply can not support TLS 1.3'. |
| Scope | FortiADC. |
| Solution |
This is by design because OpenSSL cannot support multi-keyshare options and FFDHE parameters in TLS 1.3 handshake. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.