Skip to main content
vifi
Staff
Staff
September 18, 2025

Technical Tip: FortiGate is not including AKID when resigning certificates during deep inspection

  • September 18, 2025
  • 0 replies
  • 656 views
Description This article describes why FortiGate does not include Certification Authority Key ID (AKID) when resigning certificates during SSL deep inspection.
Scope FortiGate.
Solution

When FortiGate is performing SSL deep inspection on both flow mode and proxy mode, the resigned server certificate sent by FortiGate to the end user is missing the Certification Authority Key ID (AKID).
As a result, the end user is receiving a certificate warning.

When opening the certificate, the Certification Authority Key ID is not observed:

 

Authority key id.png

 

As per RFC5280 section 4.2.1.1:

The keyIdentifier field of the authorityKeyIdentifier extension must be included in all certificates generated by conforming CAs to facilitate certification path construction.

 

This issue has been fixed in the following FortiOS versions:

  1. When firewall policy is in proxy mode or when an explicit web proxy is being used, the issue 983997 has been fixed in FortiOS versions 7.2.11 and 7.4.8.
  2. When the firewall policy is in flow mode, issue 1181573 has been resolved in FortiOS versions 7.4.10 and 7.6.5.

 

Important Note: The CA certificate used for deep inspection MUST contain Subject Key Identifier; otherwise, the Authority Key Identifier will not be included on the modified server certificate presented to the client.

 

2026-03-26 14_51_06-CLIENT(win11-France) (10.98.7.2) - Remote Desktop Connection Manager - Sysintern.png

 

Related documents:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.