Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Christian_Bootz
New Contributor

extract preshared key from config file

Dear fortinet specialists, does anybody know how to extract an encrypted preshared key from config file? The psk in our environment isn' t anywhere to be found. To avoid a completely new ipsec configuration on all devices it would be better to get the key via config file. However, the FortiClient VPN Tool creates a config file with an encryped psk inside. The same happens by saving config of the FG device. Up to now it was possible to use the FortiClient config files to get new Windows devices working. Now there' s in iPad i want to get working and so i have to enter all config data manually. Regards, Christian
2 REPLIES 2
Jan_Scholten
Contributor

hopefully the psks are save in the config files.. -> no i don' t know any way and i hope this stays that way.. imagine everyone could extract your keys out of the profiles/configs..
Christian_Bootz
New Contributor

OK, I think the psks are safe in the config files. It seems there is used md5 or sha1 to generate a checksum of the psk, usernames and also passwords and so it should be impossible to recreate readable phrases. However, there is a well known way to decrypt psks in config files saved by Cisco vpn client: http://coreygilmore.com/projects/decrypt-cisco-vpn-password/ So I thought there could be a similar way for FortiClient. Regards, Christian
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors