Chapter 1 What’s New for FortiOS 5.2.1 : Security Profiles : SSL Inspection : HTTPS Scanning Without Deep Inspection
  
HTTPS Scanning Without Deep Inspection
The following changes have been made in order to allow HTTPS traffic to be scanned without enabling deep inspection:
There are now two modes for SSL inspection: certificate inspection (certificate-inspection in the CLI), which only inspects the SSL handshake, and deep inspection (deep-inspection in the CLI), which enables full deep inspection of SSL traffic (this was previously the default mode for SSL inspection).
The CLI command https-url-scan has been removed.
deep-inspection-options has been renamed ssl-ssh-profile.
The SSL inspect-all option and the https status option now have three states: disable, certificate-inspection, and deep-inspection. The status option for the other protocols now use deep-inspection instead of enabled.
When a new policy or profile group is created, the SSL inspection profile certificate-inspection is automatically added.