FortiManager support for updated FortiOS private data encryption key
With the introduction of FortiOS 7.6.1, Fortinet has updated the private-data-encryption key feature. Administrators are no longer required to manually input a 32-digit hexadecimal private-data-encryption
key. Instead administrators simply enable the command, and a random private-data-encryption
key is generated.
Previous FortiOS CLI behavior
config system global set private-data-encryption enable end Please type your private data encryption key (32 hexadecimal numbers): 12345678901234567890123456789abc Please re-enter your private data encryption key (32 hexadecimal numbers) again: 12345678901234567890123456789abc Your private data encryption key is accepted.
New FortiOS CLI behavior
config system global set private-data-encryption enable end This operation will generate a random private data encryption key! Previous config files encrypted with the system default key cannot be restored after this operation! Do you want to continue? (y/n)y Private data encryption key generation succeeded!
FortiManager behavior
Support for the FortiGate private-data-encryption
key by the Device Manager in FortiManager 7.6.2 and earlier is unchanged. It automatically detects the remote FortiGate private-data-encryption
key status and prompts the administrator to manually type the private key (see picture below). FortiManager 7.6.2 and earlier does not support the updated, random private-data-encryption
key as the administrator will have no knowledge of the key generated in the FortiOS CLI command above. It will be supported in a later version of FortiManager.
FortiOS upgrade behavior
If in FortiOS 7.4.5 or 7.6.0 the 32-digit hexadecimal private key is enabled, and then the FortiGate device is upgraded to 7.6.1, the 32-digit hexadecimal private-data-encryption
key is preserved. As a result, FortiManager 7.6.2 and earlier is aware of the 32-digit hexadecimal private-data-encryption
key and can continue to manage the FortiGate device. However, if the private-data-encryption
key is enabled after an upgrade of FortiOS to 7.6.1, FortiManager 7.6.2 and earlier no longer can manage FortiGate devices running FortiOS 7.6.1.