Technical Tip: How to allow/block the Expired/Invalid Certificates in firewall ssl-ssh-profile
| Description | This article describes how to allow Expired/Invalid Certificates in the firewall ssl-ssh-profile. |
| Scope | FortiGate. |
| Solution | v6.0.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> set allow-invalid-server-cert [enable | disable] end
v6.2.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> config <ssl|https|ftps|imaps|pop3s|smtps> set invalid-server-cert [allow|block] end
v6.4 and above.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> config <ssl|https|ftps|imaps|pop3s|smtps> set expired-server-cert [allow|block|ignore] end
Configuration requirements.
Configuration Example to block expired and revoked certificates (showing only related elements).
SSL/SSH certificate:
F2 (Clone of deep-in~ion) # show config https Firewall policy:
config firewall policy |



