Technical Tip: FortiProxy and Explicit Web Proxy resigned certificate do not support CRL
| Description | This article describes that currently FortiProxy and Explicit Web Proxy do not support CRL distribution when resigning the certificate with deep inspection in use. |
| Scope | FortiProxy/Explicit Web Proxy. |
| Solution | FortiProxy or Explicit Web Proxy is used in order to perform deep packet inspection for traffic going to external sites. The inspection is performed with a custom CA certificate used in SSL/SSH deep inspection profile.
As a result, the access to websites is failing.
Using curl will show the following error:
curl -v --connect-timeout 15 -x http://proxy.tech:8080 https://www.heise.de
curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_NO_REVOCATION_CHECK (0x80092012) - The revocation function was unable to check revocation for the certificate.
Currently, Explicit Web Proxy and FortiProxy resigned certificate do not support CRL.
This feature can be requested by raising a New Feature Request (NFR). Contact a local sales representative to submit an NFR. |
