Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SecurityPlus
Contributor II

Security Certificate Questions

Sorry for so many questions below. I am kind of a newbie concerning security certificates.

 

[ol]
  • Are purchased (CA) security certificates a good idea when doing deep packet (SSL) inspection on a FortiGate?
  • What benefit does a purchased (CA) security certificate offer over the built in certificate?
  • What are the benefits of a commercial certificate (CA) over a self-signed certificate?
  • Are all purchased (CA) certificates the same and are they all compatible with the FortiGate?
  • If a business has a website that is externally hosted and a FortiGate and they would like a security certificate to apply to both the website and the local network (FortiGate), would this involve a different certificate?
  • Any recommendations on where to get commercial (CA) certificates?[/ol]

    Thanks in advance for any help folks can provide.

     

  • 1 Solution
    emnoc
    Esteemed Contributor III

        Are purchased (CA) security certificates a good idea when doing deep packet (SSL) inspection on a FortiGate?

     

    Typically  you use your   internal  CA and publish that certficate via a windows GPO or manual input ( non-windows devices).  read below for why it's good.

     

     

        What benefit does a purchased (CA) security certificate offer over the built in certificate?

     

    Provides trust from a trusted CAchain, a big plus.

    Provide life-time

    Low-maint ( no need to distribute or import for the most part )

     

        What are the benefits of a commercial certificate (CA) over a self-signed certificate?

     

    Provides trust from a wellknown CAchain, see above about management and import. You only need to import into the fortigate-proxyssl for inspection, a  browser will typically honor the publicCA issued cert if it's from a well-knownCA.

     

     

        Are all purchased (CA) certificates the same and are they all compatible with the FortiGate?

     

    yes,  they compatible just like a self-sign. Even a CA-issued is technically "self-signed" ;) Just make sure to get a cert from a well known  CA

     

     

        If a business has a website that is externally hosted and a FortiGate and they would like a security certificate to apply to both the website and the local network (FortiGate), would this involve a different certificate?

     

    A cert on a website for example,  is a SeverCert, the cert for sslproxyis a CAtrue certificate both follow x509 but the purpose is  NOT  mutually the same. So  yes you need a webserver-certificate(s) and SSLproxy certificate.

        Any recommendations on where to get commercial (CA) certificates?

     

    Shop around geotrust,entrust,godaddy,etc..... Cost could be a few hundred or so dollar but they are affordable

    PCNSE 

    NSE 

    StrongSwan  

    View solution in original post

    PCNSE NSE StrongSwan
    14 REPLIES 14
    SecurityPlus

    Any feedback on the most recent questions? Thanks
    sw2090
    Honored Contributor

    Addtiionally: for deep inspection you need a certificate that is able to sign new certs because deep inspection is somewhat man-in-the-middle. Your FGT will not accept a standard ssl server certs for this...

    -- 

    "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

    -- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
    boneyard
    Valued Contributor

    SecurityPlus are you in control of those devices? if you are then you might have a MDM (mobile device management) solution which you can use to distribute these CA certificates to your phones and tablets.

     

    if you don't control the devices there isn't an easy solution. this is something more people run into with SSL inspection so perhaps some googling will get you tools or software that can handle this.

     

    in general you can't buy SSL CA certificates for inspection. if you could then you would break the whole principle SSL certificates are based on.

    sw2090
    Honored Contributor

    yes you cannot buy a CA but you can buy a sub-ca ...

    -- 

    "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

    -- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
    boneyard
    Valued Contributor

    show me where i can buy a public sub CA certificate please?

    Labels
    Top Kudoed Authors