FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dkochhar
Staff
Staff
Article Id 383014
Description This article describes an issue where the status of the FSSO secure connection appears as down due to poor key strength.
Scope FortiGate.
Solution The FSSO secure connection is displayed as down.

FSSO-1.png

 

In the Packet Captures, the FortiGate has sent 'Alert (Level: Fatal, Description: Bad Certificate)'.

This alert message is triggered when FortiGate is unable to validate the server certificate presented by the Collector agent.

 

FSSO.png

 
Ensure that the certificate's key strength is not too low. The certificate used for establishing the FSSO SSL connection should have a minimum key strength of 2048 bits.

 

FSSO-2.png