Skip to main content
Dongfang_Li_FTNT
Staff
Staff
July 6, 2022

Technical Tip: Certificate Error in Admin Access

  • July 6, 2022
  • 0 replies
  • 13878 views

Description

This article describes how to resolve an issue where, when a user connects to FortiGate GUI using the FortiGate IP address, the web page displays the certificate error: ERR_CERT_COMMON_NAME_INVALID.

Scope

FortiGate.

Solution

The following certificate error is seen.

 

Dongfang_Li_FTNT_0-1657142449240.png

 

The Common Name represents a server name protected by the SSL certificate.  The certificate is valid only if the requested hostname matches the certificate's common name.

 

Check the Certificate, it is issued to *****.com:

 

Dongfang_Li_FTNT_1-1657142449246.png

 

 

The user connects to the IP address https://x.x.x.x. The certificate's common name is *****.com, which does not match. The certificate should be issued to the IP address x.x.x.x, or the user should connect to the URL *****.com.


If Certificates are not visible in GUI, enable them from System -> Feature Visibility -> Additional Features -> Certificates.


To create a custom certificate issued to the FortiGate IP address, create a new CSR in FortiGate, in Subject Information, ID Type, enable 'Host IP', and put IP x.x.x.x. In the GUI this can be done from System -> Certificates -> Create/Import -> Generate CSR:


CSR_modif.png

 

Complete the CSR, download it, have it signed by an internal Certificate Authority, and import it back to FortiGate. Publicly-trusted Certificate Authorities such as Symantec, Comodo, GoDaddy, and Let'sEncrypt will not sign a certificate issued to an IP address.  

 

Once the certificate is imported back to FortiGate, assign it to the admin access:

 

config system global

set admin-server-cert <certificate_name>

end


It is also worth noting that the Google Chrome and some other browsers have remove support for CommonName (CN) matching in certificates. Subject Alternative Name (SAN), which is marked in above snapshot, has been mandatory in the most recent version of Google Chrome.
This means if the SAN field is empty or different from the FQDO/IP address used to access the FortiGate GUI, the error of 'ERR_CERT_COMMON_NAME_INVALID' will still occur. Reference: Deprecations and Removals in Chrome 58.

Alternative Method: Fortinet_GUI_Server certificate:
In the newer v7.2.1 onwards, the default Fortinet_GUI_Server certificate contains the IP addresses of the interfaces on which HTTPS is enabled. The certificate is signed by the FortiGate's own local Certificate Authority Fortinet_CA_SSL. See GUI Untrusted HTTPS server certificate or the steps below.

 

Configure the Fortinet_GUI_Server certificate under System -> Setting -> Administration Settings -> HTTPS server certificate.

 

Screenshot 2024-08-22 155836.png

 

After, install the Fortinet CA SSL on the PC as a Trusted Root Certificate. The error will be removed. The Fortinet CA SSL certificate can be downloaded from System -> Certificate->Fortinet_CA_SSL.


ca.png



Related articles:

Technical Tip: How to assign a SSL certificate for remote administration of FortiGate

Generating a CSR on a FortiGate

Technical Tip: Adding SAN (Subject Alternative Name) while generating CSR (Certificate Signing Request) 

Troubleshooting Tip: A guide to FortiGate and certificate issues 

Technical Tip: GUI Untrusted HTTPS server certificate 

Technical Tip: Certificate warning while accessing FortiGate

 

Related Video:

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!