Certificates Flashcards

1
Q

Which attribute or extension identifies the owner of a certificate?

A

The subject name

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which configuration requires FortiGate to act as a CA for full SSL inspection?

A

Multiple clients connecting to multiple servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which inspection mode can protect your LAN devices from encrypted malware?

A

Deep inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What certificate standard does FortiGate use?

A

X.509v3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who acts as the FortiGate OSCP responder?

A

FortiAuthenticator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does FortiGate check before trusting and using a certificate?

A
  • Revocation check
  • CA certificate possession (issuer)
  • Validity dates
  • Digital signature validation
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does FortiGate verify a digital signature?

A
  • Runs certificate through a hash function/algorithm
  • FortiGate hash result must match the CA result
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is SSL inspection mode used for?

A
  • Web filtering
  • Application control
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does SSL inspection do?

A
  • FortiGate inspects the certificate and packet header
  • Then, checks for a match between the site visited and the certificate presented
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does FortiGate act as in full SSL inspection?

A

Main-in-the-middle proxy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a difference between SSL inspection and full SSL inspection?

A
  • SSL inspection does not decrypt packets
  • Full SSL inspection decrypts and encrypts packets using its own keys
  • In full SSL inspection, FortiGate can inspect the traffic
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do sessions work in full SSL inspection mode?

A
  • Two separate SSL sessions are maintained
  • Client-To-FortiGate, and FortiGate-to-server
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Where can you select the SSL inspection mode?

A

At the firewall policy level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the pre-defined SSL profiles?

A
  • no-inspection
  • deep-inspection
  • certificate-inspection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What should you do if you want to modify a SSL profile?

A
  • Use custom deep-inspection
  • Pre-defined profiles cannot be modified
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Why might you exempt sites from SSL inspection?

A
  • Problems with traffic (ex. HSTS)
  • Legal issues
17
Q

How does FortiGate inspect encrypted traffic?

A

Intercepts the certificate coming from the server, then generates a temporary one

18
Q

What certificate is installed by default on FortiGate?

A
  • A self-signed encrypting SSL CA certificate
  • Fortinet_CA_SSL
19
Q

How would you avoid warnings on a user device when using the default FortiGate Self-Signed certificate?

A
  • Install CA certificate Fortinet_CA_SSL as a trusted CA on user devices (import into browsers)
  • Install a company CA certificate on FortiGate for full SSL inspection
20
Q

What is a certificate requirement for full SSL inspection?

A

Requires that FortiGate acts as a CA to generate an SSL private key and certificate

21
Q

What is the default SSL inspection profile?

A

no-inspection

22
Q

What are limitations of the no-inspection profile?

A
  • No web filtering
  • No application control
23
Q

Where can you find the FortiGate HTTPS Server Certificate?

A

System > Settings

24
Q

What functions would you need to import a private certificate for?

A
  • FortiGate GUI
  • SSL-VPN tunnels
25
Q

What error is NET::ERR_CERT_AUTHORITY_INVALID indicative of?

A

HSTS issues

26
Q

What is a possible workaround for sites with an HSTS requirement that having issues?

A
  • Exempt websites from full SSL inspection
  • Use SSL certificate inspection instead
  • Adjust browser settings