6.1.1 Apply a Trusted Signed Certificate for VPN Portal

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Apply a signed certificate from a trusted Certificate Authority (CA) to the SSL VPN portal to allow users to connect securely with confidence

Rationale:

Having an unsigned or self signed certificate leaves connections open to man-in-the-middle attacks and could allow users to connect to untrusted servers

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Import a signed certificate from a trusted CA through the GUI

System > Certificates > Import and then assign the certificate to the SSL VPN portal by going to VPN > SSL-VPN Settings and selecting the proper certificate in the dropdown for 'Server Certifcate'

Default Value:

Self Signed Factory installed certificate

See Also

https://workbench.cisecurity.org/files/4077

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(2)

Plugin: FortiGate

Control ID: cfd8140797a1ecbfd800433470d43da8ec5d36739f59e36a7e28e474f5b1c8b8