Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aseques
New Contributor

Fortigate ssl proxy private keys are different on every backup, diffing not possible

I have a little script that uses scp to download the current configuration to my server, there's a second part of the script that does a diff with both files and warns me when there have been modifications.

I am having an issue with the  private keys for "Fortinet_CA_SSLProxy"  and for "Fortinet_SSLProxy", weird enough the certificates are the same all the time, so i'm a bit lost here. Aren't the backups mean to be identical? (other than the  conf_file_ver)?

 

1 Solution
jmlux
New Contributor III

I haven't asked support (yet), but I have found out the following:

 

Different types of configuration output / backup are available (output=backup in this case since everything is a text file, kudos, Fortinet):

[ul]
  • show (like backup but without certificates)
  • show full (very verbose, includes default config, and always changing stuff)
  • execute backup (like "show" but with certificates)[/ul]

    You only notice stuff changing when comparing different "show full"s.

    Meaning: Since "execute backup" (=the backup function in the GUI) is not a lot more verbose than a simple "show", it follows from that that the always changing information is not required to accomplish an actual restore. So why back it up?

     

    Now those findings would have to be confirmed by someone ;)

  • View solution in original post

    11 REPLIES 11
    jmlux
    New Contributor III

    According to my previous statement that "show" didn't include cycling private keys and/or certificates, I found out that this is not always true. It seems true on e.g. a 100D/FOS5.2.5 (no vdoms), but not a 400D/FOS5.2.6 (with vdoms)...

    aseques
    New Contributor

    The solution I am using with the diffed config files is still working fortunately (not tried with 5.2.6 yet), so until fortigate allows a proper scp backup download I'll keep using this method.

    Thanks for testing in 5.2.6

    Labels
    Top Kudoed Authors