FortiADC
FortiADC enhances the scalability, performance, and security of your applications whether they are hosted on premises or in the cloud.
okhatab
Staff
Staff
Article Id 349723

 

Description

This article describes why FortiADC will not allow enabling RFC 7919 Comply when SSLv3 or TLSv1.3 is selected in Allowed SSL Version in Client SSL profiles and will generate an error stating 'Client SSL RFC7919 Comply can not support TLS 1.3'.

Scope FortiADC.
Solution

This is by design because OpenSSL cannot support multi-keyshare options and FFDHE parameters in TLS 1.3 handshake.


image.png