Sorry for so many questions below. I am kind of a newbie concerning security certificates.
[ol]
Thanks in advance for any help folks can provide.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Are purchased (CA) security certificates a good idea when doing deep packet (SSL) inspection on a FortiGate?
Typically you use your internal CA and publish that certficate via a windows GPO or manual input ( non-windows devices). read below for why it's good.
What benefit does a purchased (CA) security certificate offer over the built in certificate?
Provides trust from a trusted CAchain, a big plus.
Provide life-time
Low-maint ( no need to distribute or import for the most part )
What are the benefits of a commercial certificate (CA) over a self-signed certificate?
Provides trust from a wellknown CAchain, see above about management and import. You only need to import into the fortigate-proxyssl for inspection, a browser will typically honor the publicCA issued cert if it's from a well-knownCA.
Are all purchased (CA) certificates the same and are they all compatible with the FortiGate?
yes, they compatible just like a self-sign. Even a CA-issued is technically "self-signed" ;) Just make sure to get a cert from a well known CA
If a business has a website that is externally hosted and a FortiGate and they would like a security certificate to apply to both the website and the local network (FortiGate), would this involve a different certificate?
A cert on a website for example, is a SeverCert, the cert for sslproxyis a CAtrue certificate both follow x509 but the purpose is NOT mutually the same. So yes you need a webserver-certificate(s) and SSLproxy certificate.
Any recommendations on where to get commercial (CA) certificates?
Shop around geotrust,entrust,godaddy,etc..... Cost could be a few hundred or so dollar but they are affordable
PCNSE
NSE
StrongSwan
Addtiionally: for deep inspection you need a certificate that is able to sign new certs because deep inspection is somewhat man-in-the-middle. Your FGT will not accept a standard ssl server certs for this...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
SecurityPlus are you in control of those devices? if you are then you might have a MDM (mobile device management) solution which you can use to distribute these CA certificates to your phones and tablets.
if you don't control the devices there isn't an easy solution. this is something more people run into with SSL inspection so perhaps some googling will get you tools or software that can handle this.
in general you can't buy SSL CA certificates for inspection. if you could then you would break the whole principle SSL certificates are based on.
yes you cannot buy a CA but you can buy a sub-ca ...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
show me where i can buy a public sub CA certificate please?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.