Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nneul
New Contributor

Is there any way to get consistent/repeatable "set password ENC" and "set private-key" output?

Currently, it looks like the unit (3001F on 7.2.6) will use a different seed or other value when outputting configuration in a 'show' or 'show full-configuration'. This makes it different to watch for changes/etc. if tracking the configuration in an external system.

 

Is there any way to get a consistent seed/encryption so that they aren't different values on every invocation?

 

I'm open to retrieving the configuration using some other mechanism/api endpoint/etc. if needed.

1 Solution
kcheng
Staff
Staff

Hi @nneul 

 

Unfortunately, that is not possible. You may refer to the following article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Constant-changing-of-password-and-encrypte...

 

The reason behind this is that if the enc value remains the same, it will be vulnerable to attack. Hope that clarifies.

Cheers,
Kayzie Cheng

If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

1 REPLY 1
kcheng
Staff
Staff

Hi @nneul 

 

Unfortunately, that is not possible. You may refer to the following article:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Constant-changing-of-password-and-encrypte...

 

The reason behind this is that if the enc value remains the same, it will be vulnerable to attack. Hope that clarifies.

Cheers,
Kayzie Cheng

If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors