Skip to main content
johnathan
Staff
Staff
July 21, 2026

Technical Tip: 'Invalid wildcard certificate' is seen when trying to connect a FIPS FortiGate to a FortiAnalyzer

  • July 21, 2026
  • 0 replies
  • 56 views

Description

This article describes why 'Invalid wildcard certificate' is seen when trying to connect a FIPS FortiGate to a FortiAnalyzer.

Scope

FortiOS in FIPS mode.

Solution

When connecting a FortiGate in FIPS mode to a FortiAnalyzer, a certificate for client authentication must be presented to the FortiAnalyzer. 
More details on the certificate requirements for this connection can be seen here:
Technical Tip: FortiGate is not able to send logs to FortiAnalyzer with FIPS -CC mode enabled in version 7.2.5

After trying to select a certificate with 'set certificate xxxxx', 'Invalid wildcard certificate' may be seen:

9aa9b6fa.png


This is because of the SAN in the Certificate. The certificate used for this purpose cannot have more than one subdomain in its SAN. For example, www.xxx.yyy.zzz will not work, but xxx.yyy.zzz will.

'client-bad' will hit this issue, as there are two subdomains:

63e089b6.png



'client-good' will not hit this issue, as there is only one subdomain:

573fbf87.png


When 'client-good' is used, the FortiGate accepts it:

96a0182b.png

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!