Enhanced administrator password security 7.2.11
The PBKDF2 hashing scheme with randomized salts is now used to store system administrator passwords on the FortiGate to enhance security. Previously the SHA256 hashing algorithm was used.
With this change, a new command is available to maintain FortiOS downgrade:
config system password-policy
set login-lockout-upon-downgrade {enable | disable}
end
For more information about this feature, see Enhanced administrator password security.