NSE4 · Question #259
When the SSL proxy inspects the server certificate for Web Filtering only in SSL Handshake mode, which certificate field is being used to determine the site rating?
The correct answer is A. Common Name. When the SSL proxy performs web filtering in SSL Handshake mode, it uses the Common Name (CN) field from the server certificate to identify the website for rating.
Question
When the SSL proxy inspects the server certificate for Web Filtering only in SSL Handshake mode, which certificate field is being used to determine the site rating?
Options
- ACommon Name
- BOrganization
- COrganizational Unit
- DSerial Number
- EValidity
How the community answered
(36 responses)- A86% (31)
- B6% (2)
- C6% (2)
- E3% (1)
Why each option
When the SSL proxy performs web filtering in SSL Handshake mode, it uses the Common Name (CN) field from the server certificate to identify the website for rating.
When a FortiGate performs SSL inspection in SSL Handshake mode for web filtering, it inspects the server's certificate during the TLS handshake. The Common Name (CN) field (or Subject Alternative Name - SAN) within the certificate is primarily used to identify the domain name of the website, which is then queried against the web filtering database to determine its category and rating.
The Organization field specifies the legal entity owning the certificate, not the domain name of the website for content rating.
The Organizational Unit field specifies a division within the organization, which is not used for website content categorization.
The Serial Number is a unique identifier for the certificate itself, not used to determine the website's content rating.
The Validity period indicates when the certificate is active, which is not used for determining the website's content rating.
Concept tested: FortiGate SSL inspection Web Filtering CN usage
Source: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-FortiGate-Web-Filter-works-with-HTTPS-traffic/ta-p/192257
Topics
Community Discussion
No community discussion yet for this question.