update_ssl_ssh_profile
Update the CA for re-signing certificates in an SSL/SSH inspection profile to ensure client trust and address 512-bit key issues on FortiGate-VM evaluation licenses.
Instructions
Update an SSL/SSH inspection profile, e.g. the CA used to re-sign certificates during deep inspection. Clients must trust that CA, and FortiGate-VM evaluation licenses re-sign RSA sites with 512-bit keys regardless of the CA, which modern clients reject.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Profile name, e.g. custom-deep-inspection | |
| vdom | No | VDOM (default: FORTIGATE_VDOM, usually root) | |
| extra | No | Extra FortiOS attributes merged into the request body as-is (hyphenated keys) | |
| caname | No | CA certificate used to re-sign trusted sites | |
| comment | No | Comment | |
| untrusted_caname | No | CA used to re-sign sites with untrusted certificates |