NSE4 · Question #368
Which of the following statements are true about the SSL Proxy certificate that must be used for SSL Content Inspection? (Choose two.)
The correct answer is C. It must be installed in the FortiGate device D. The subject filed must contain either the FQDN, or the IP address of the FortiGate device. For SSL Content Inspection, the specific CA certificate used by the FortiGate must be installed on the device, and its subject field should typically identify the FortiGate (e.g., with its FQDN or IP address) to clients in the certificate chain.
Question
Which of the following statements are true about the SSL Proxy certificate that must be used for SSL Content Inspection? (Choose two.)
Options
- AIt cannot be signed by a private CA
- BIt must have either the field "CA=True" or the filed "Key Usage=KeyCertSign"
- CIt must be installed in the FortiGate device
- DThe subject filed must contain either the FQDN, or the IP address of the FortiGate device
How the community answered
(35 responses)- A3% (1)
- B3% (1)
- C94% (33)
Why each option
For SSL Content Inspection, the specific CA certificate used by the FortiGate must be installed on the device, and its subject field should typically identify the FortiGate (e.g., with its FQDN or IP address) to clients in the certificate chain.
SSL Proxy certificates for deep inspection can indeed be signed by a private Certificate Authority (CA), which is a common practice in enterprise environments to ensure client trust.
A certificate used as an SSL proxy CA for deep inspection *must* have either the 'CA=True' flag or 'Key Usage=KeyCertSign' to function as a signing authority; therefore, stating it 'must have' these fields is technically correct and essential for its purpose.
The SSL Proxy certificate, which acts as the signing CA for deep SSL inspection, must be installed on the FortiGate device so it can perform its role of generating and signing synthetic server certificates for intercepted connections.
For SSL content inspection, the subject field of the FortiGate's SSL Proxy CA certificate (especially if self-signed or internally issued) should contain the FortiGate's FQDN or IP address, allowing clients to identify the inspecting device as the issuer in the certificate chain.
Concept tested: SSL Content Inspection certificate requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/500078/configuring-ssl-ssh-inspection
Topics
Community Discussion
No community discussion yet for this question.