QuestionQ18

Network Security Support Engineer

Consider a situation in which the server name indication (SNI) does not match either the common name (CN) or any subject alternative name (SAN) in the server certificate.

With the default SSL certificate-inspection settings, what action will FortiGate take?

  • A FortiGate closes the connection because this represents an invalid SSL/TLS configuration.
  • B FortiGate uses the CN information from the Subject field in the server certificate.
  • C FortiGate uses the first entry listed in the SAN field in the server certificate.
  • D FortiGate uses the SNI from the user’s web browser.
Explanation

With the default enabled server-certificate SNI check for SSL certificate inspection, an SNI mismatch causes FortiGate to use the common name (CN) in the server certificate for URL filtering. Connection termination occurs only when the SNI check is configured as strict. Fortinet: Configuring an SSL/SSH inspection profile

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!