Technical Tip: FortiGate is not including AKID when resigning certificates during deep inspection
| Description | This article describes why FortiGate does not include Certification Authority Key ID (AKID) when resigning certificates during SSL deep inspection. |
| Scope | FortiGate. |
| Solution | When FortiGate is performing SSL deep inspection on both flow mode and proxy mode, the resigned server certificate sent by FortiGate to the end user is missing the Certification Authority Key ID (AKID).
As per RFC5280 section 4.2.1.1: The keyIdentifier field of the authorityKeyIdentifier extension must be included in all certificates generated by conforming CAs to facilitate certification path construction.
This issue has been fixed in the following FortiOS versions:
Important Note: The CA certificate used for deep inspection MUST contain Subject Key Identifier; otherwise, the Authority Key Identifier will not be included on the modified server certificate presented to the client.
Related documents: |


