| Description | This article describes how to generate or re-generate SSH Server Host Key in the FortiManager/FortiAnalyzer OS in compliance with the operation management function with FIPS-CC. The encryption algorithm types ECDSA, EdDSA, and RSA will be generated. |
| Scope | FortiManager/FortiAnalyzer version 7.2.3 and above, version 7.4.0 and above. |
| Solution |
execute ssh-regen-keys.
An example run in FortiAnalyzer:
execute ssh-regen-keys Regenerating SSH keys...done.
id=7274506179345121282 bid=50480 dvid=1040 itime=1693727956 euid=1 epid=1 dsteuid=1 dstepid=1 log_id=0001010090 subtype=system type=event level=notice time=15:59:16 date=2023-09-03 user=sshd desc=SSH server regenerate host keys operation=Generate host key performed_on=SSH server changes=Generated new ECDSA host key tz=+0800 devid=FAZ-VM0000109999 devname=FAZ-74 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.