Created on 03-02-2023 10:02 PM Edited on 07-27-2023 01:54 AM By Jean-Philippe_P
Description |
This article describes that after an upgrade from LENC to High Encrypt, the deep inspection does not work.
It is possible to review using curl or OpenSSL that interchange certificate has 512 bits.
subject=CN = www.globo.com
Having the default CA with a lower key will limit the on-the-fly certificate generation for deep inspection, even if using the own CA. |
Scope | Upgrading from LENC mode some certificates may not get regenerated. |
Solution |
Execute command:
execute vpn certificate local generate default-ssl-ca
This regenerates the certificate templates for deep-inspection. It can be possible to have to reboot in other for new certificates and keys to take place.
If having a cluster, it could be possible to follow the below steps to renew all default CAs and certificates in other:
Example: https://i.imgur.com/gejvNNl.png
execute ha manage ?
Type 'y'.
execute reboot
Type 'y'.
config system ha |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.