Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gfuzz
New Contributor

REST API Availability in FIPS-CC mode

Hello everyone,

 

As for i know, REST API Administrators should be disabled by default in FIPS-CC mode:

1) (REST API admin account option is not avai... - Fortinet Community)

2) (Solved: Re: Fortigate 3301E missing API 7.2.11 - Fortinet Community)

 

I'm new to Fortinet, and i'm currently configuring a Fortigate61F with firmware version v7.2.8 build9703 (FIPS-CC-72-5), downloaded following instructions from this article (Extended Support for v7.0 FIPS-CC Certifi... - Fortinet Community).

 

  • Command "get system status" shows "FIPS-CC mode: enable"
  • Creating an admin from:  System - Administrators - New - REST API Admin, succeed.
  • APIs works as expected.

 

I haven't found anything related REST API in FIPS-CC mode in the FortiOS 7.2.8 Release Note.

Is this the intended behavior or i have made some mistakes enabling FIPS mode?

 

Thanks in advance!

 

 

1 REPLY 1
kaman
Staff
Staff

Hi gfuzz,

As you mentioned, you haven't found anything related REST API in FIPS-CC mode in the FortiOS 7.2.8

The REST API admin account option is not available for FIPS-CC mode. By design, the REST API user for FIPS-CC is disabled.

Please refer to the documents below for more information:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-REST-API-admin-account-option-is-not-avail...

https://docs.fortinet.com/document/fortigate/6.4.0/administration-guide/399023/rest-api-administrato...


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors