Description | This article explains how to disable TLS 1.0 and TLS 1.1 in FortiPAM. |
Scope | FortiPAM v1.3 and v1.4. |
Solution |
This is a general TLS version control configuration, which controls LDAP-based authentication, password-changer, and secret discovery. Also controls general communications with FortiToken Cloud, FortiGuard, FortiAnalyzer, etc.
config firewall VIP
This is the TLS version control for FortiPAM GUI access as well as ZTNA tunnel under Secrets -> Secret Setting -> Tunnel Encryption TLS version of native secret launchers.
From GUI: Go under Advanced Domain Setting -> LDAPS Minimum SSL Version (default follow system global setting, TLS 1.2 and above).
From CLI:
config secret target end
Controls the LDAPs-based password-changer, discovery etc. This config could overwrite the System -> Global -> ssl-min-proto-version config.
config user ldap -> set ssl-min-proto-version <----- Default follow system global setting, which is tls 1.2 and above.
Controls the LDAP-based FortiPAM users authentication. This config could overwrite the System -> Global -> ssl-min-proto-version config.
To change this config, go to:
config firewall ssl-ssh-profile
config firewall policy
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.