Skip to main content
vifi
Staff
Staff
November 25, 2025

Technical Tip: FortiProxy and Explicit Web Proxy resigned certificate do not support CRL

  • November 25, 2025
  • 0 replies
  • 495 views
Description This article describes that currently FortiProxy and Explicit Web Proxy do not support CRL distribution when resigning the certificate with deep inspection in use.
Scope FortiProxy/Explicit Web Proxy.
Solution

FortiProxy or Explicit Web Proxy is used in order to perform deep packet inspection for traffic going to external sites.

The inspection is performed with a custom CA certificate used in SSL/SSH deep inspection profile.


The issue is that the replacement certificate created by the FortiProxy/Explicit Web Proxy during deep inspection doesn't contain CRL.

As a result, the access to websites is failing.

 

Using curl will show the following error:

 

curl -v --connect-timeout 15 -x http://proxy.tech:8080 https://www.heise.de

 

curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_NO_REVOCATION_CHECK (0x80092012) - The revocation function was unable to check revocation for the certificate.

 

Currently, Explicit Web Proxy and FortiProxy resigned certificate do not support CRL.

 

This feature can be requested by raising a New Feature Request (NFR). Contact a local sales representative to submit an NFR.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!