FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
odahy
Staff
Staff
Article Id 359132
Description This article describes the allowed types of ECC Certificates when enabling FIPS on FortiGate.
Scope FortiOS.
Solution

When FIPS mode is enabled in the FortiOS some already imported  ECC (Elliptical curve cryptography) certificates might not work as intended.

As the FortiGate under this mode will only allow ECC certificates using ECDSA Elliptic curves, a digital signature algorithm using NIST curves will be as follows: (P192, P-224, P-256, P-384 and P-521).

 

More regarding the approved ECDSA approved curves can be read in NIST.FIPS.186-4.
See the image below for an example of an unapproved ECDSA Certificate using brainpool curves instead of NIST curves:

Screenshot 2024-11-21 104357.png

Contributors