Description | This article describes how to generate or re-generate SSH Server Host Key in the FortiManager/FortiAnalyzer OS in compliance with the operation management function with FIPS-CC. The encryption algorithm types ECDSA, EdDSA, and RSA will be generated. |
Scope | FortiManager/FortiAnalyzer version 7.2.3 and above, version 7.4.0 and above. |
Solution |
execute ssh-regen-keys.
An example run in FortiAnalyzer:
execute ssh-regen-keys Regenerating SSH keys...done.
id=7274506179345121282 bid=50480 dvid=1040 itime=1693727956 euid=1 epid=1 dsteuid=1 dstepid=1 log_id=0001010090 subtype=system type=event level=notice time=15:59:16 date=2023-09-03 user=sshd desc=SSH server regenerate host keys operation=Generate host key performed_on=SSH server changes=Generated new ECDSA host key tz=+0800 devid=FAZ-VM0000109999 devname=FAZ-74 |