2.1.8 Disable static keys for TLS

Information

Disable support for static keys on TLS sessions terminating on the FortiGate

Rationale:

Prevent TLS sessions terminating on the FortiGate from using static SSL keys

Solution

CLI:

config system global

set ssl-static-key-ciphers disable

end

Default Value:

set ssl-static-key-ciphers enable

See Also

https://workbench.cisecurity.org/benchmarks/12961