3 ms·
They won't even create a fix for their software after blatantly disabling TLS server validation in their FortiSIEM product: https://packetstormsecurity.com/file
by precurse 7y ago
They won't even create a fix for their software after blatantly disabling TLS server validation in their FortiSIEM product: https://packetstormsecurity.com/files/154702/Fortinet-FortiSIEM-5.0-5.2.1-Improper-Certification-Validation.html https://packetstormsecurity.com/files/154702/Fortinet-FortiS...
They use the "-k" curl flag throughout their code (disabling ALL certificate validation), since I assume is to make initial configuration easier. Rather than fix this going forward, they created a workaround document which all new and existing customers need to follow to secure their setup.