Digital Certificates Flashcards

1
Q

How does Fortigate use digital certificates?

A

Inspection
Privacy (SSL connections)
Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What standard of certificates does Fortigate support?

A

X.509v3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does FortiGate validate certificates before trusting it?

A

Checks local CRL (serial number)
Reads Issuer field to see if it has the corresponding CA certificate.
Verifies date validity
Verifies the digital signature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a fresh hash?

A

Is formed when Fortigate runs the digital cert through the specified has.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the original hash?

A

It is when the CA runs the digital cert through its hashing algorithm and then encrypts it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Does Fortigate need SSL to connect to FortiGuard?

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What can SSL Certificate inspection help you secure? (three things)

A

Verify ID of web serverse
Web filtering
Application control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

In order to allow FTG to act as a CA what two extensions need to be configured?

A

cA=True
keyUsuage=keyCertSign

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

For SSL deep inspection: does FTG need to have a chain of CA certificates installed?

A

Yes, so that the client can verify and build a chain of trust.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What must you select in SSL/SSH inspection profiles to do outbound connections?

A

You must select Multiple Clients Connecting to Multiple Servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the three options for untrusted SSL certificates?

A

Allow, Block, Ignore

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does allow Untrusted SSL certificates do?

A

Fortigate sends a temporary cert signed with its built-in Fortinet_CA_Untrusted certificate. A warning pops up on the browser.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What will happen if you don’t import the Fortinet SSL certificate into the users browser?

A

A warning will be presented even if Fortinet trusts the original SSL certificate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What will happen if you ignore untrusted browser certificates?

A

Fortigate sends a temporary cert for all trusted or untrusted certificates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does HPKP stand for?

A

HTTP public key pinning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What makes a SSL certificate invalid?

A

Expired
Revoked
Validation timeout (communication timeout)
Validation failed (communication error)

17
Q

To protect inbound SSL traffic what option must you select?

A

Protecting SSL Server

18
Q

When doing inbound SSL inspection, what do you install to get trust from the browser?

A

The chain of certificates for the client to build the chain of trust.

19
Q
A