NSE4 · Question #462
Which of the following statements are true about Man-in-the-middle SSL Content Inspection? (Choose three.)
The correct answer is B. The FortiGate device acts as a sub-CA C. The local service certificate of the web server must be installed in the FortiGate device E. The required SSL Proxy certificate must first be requested to a public certificate authority (CA). Man-in-the-middle SSL Content Inspection requires the FortiGate to act as a sub-CA, using its own SSL Proxy certificate (which client devices must trust) to dynamically sign and present certificates to clients, effectively intercepting and re-encrypting traffic.
Question
Which of the following statements are true about Man-in-the-middle SSL Content Inspection? (Choose three.)
Options
- AThe FortiGate device "re-signs" all the certificates coming from the HTTPS servers
- BThe FortiGate device acts as a sub-CA
- CThe local service certificate of the web server must be installed in the FortiGate device
- DThe FortiGate device does man-in-the-middle inspection.
- EThe required SSL Proxy certificate must first be requested to a public certificate authority (CA).
How the community answered
(34 responses)- A6% (2)
- B82% (28)
- D12% (4)
Why each option
Man-in-the-middle SSL Content Inspection requires the FortiGate to act as a sub-CA, using its own SSL Proxy certificate (which client devices must trust) to dynamically sign and present certificates to clients, effectively intercepting and re-encrypting traffic.
The FortiGate device generates *new* certificates for the client, signed by its own CA certificate, rather than directly re-signing the original server certificates.
In Man-in-the-middle SSL Content Inspection, the FortiGate device essentially functions as a 'sub-CA' by dynamically generating and signing new certificates for the client for each SSL connection it inspects, using its own CA certificate.
For Man-in-the-middle SSL inspection, the FortiGate requires its own 'SSL Inspection CA' certificate (often referred to as a local service certificate) to be trusted by client browsers, which it uses to dynamically sign certificates presented to clients.
This statement is too general and merely reiterates that the FortiGate performs man-in-the-middle inspection, failing to describe specific operational details as requested by the question.
The 'SSL Proxy certificate' is the FortiGate's CA certificate used to sign dynamically generated server certificates. For trusted operation without client warnings, this CA certificate must be trusted by clients, often by being issued by an internal CA or, less commonly, a public CA, or by manual installation.
Concept tested: FortiGate SSL Deep Inspection (MITM) mechanics
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/35889/ssl-ssh-inspection
Topics
Community Discussion
No community discussion yet for this question.