FCSS_LED_AR-7.6 · Question #62
In each user certificate, you can define the subject field, expiration date. User Principal Name (UPN), URL for CRL download, and the OCSP URL. How does the detailed configuration of these…
The correct answer is C. It enables precise identification of the user and ensures timely certificate revocation checks. In user certificates used with FortiGate / FortiAuthenticator / SSL-VPN / 802.1X, the following attributes are important: Subject field & UPN Provide a unique identity for the user (CN and/or UPN). FortiGate can use theSAN/UPNfield for LDAP-integrated certificate…
Question
In each user certificate, you can define the subject field, expiration date. User Principal Name (UPN), URL for CRL download, and the OCSP URL. How does the detailed configuration of these attributes impact the certificate?
Options
- AIt makes the certificate easier to revoke manually because it reduces the need for automatic
- BIt limits the validity of the certificate to specific devices and applications, reducing its general
- CIt enables precise identification of the user and ensures timely certificate revocation checks.
- DIt makes the certificate compatible with a wide range of applications and services by ensuring
How the community answered
(38 responses)- A3% (1)
- B3% (1)
- C87% (33)
- D8% (3)
Explanation
In user certificates used with FortiGate / FortiAuthenticator / SSL-VPN / 802.1X, the following attributes are important: Subject field & UPN Provide a unique identity for the user (CN and/or UPN). FortiGate can use theSAN/UPNfield for LDAP-integrated certificate authentication. Limits how long the certificate is valid, enforcing lifecycle and rotation. CRL URL & OCSP URL Tell FortiGate (or any relying party)where to check if the certificate has been revoked. Enablesnear real-time revocationusing OCSP or periodic CRL downloads instead of relying only By carefully configuring these fields: The certificate uniquely and correctly identifies the user. Relying systems can performaccurate and timely revocation checks, improving security.
Topics
Community Discussion
No community discussion yet for this question.