Skip to main content
js2
Staff
Staff
May 9, 2020

Technical Tip: Self-signed certificate error

  • May 9, 2020
  • 0 replies
  • 5285 views
Description
This article describes the error 'Your connection is not private' when a web server is hosted behind FortiGate and not accessible via HTTPS.

Solution
If FortiGate default certificate is used, it is expected that the certificate error will be shown since it is a self-signed CA and it will not be trusted by any browsers.
If the certificate is already signed and if the CSR is generated on a different computer then:

- The certificate in CRT/DER format is needed and the private key in PEM format and then import both the files as local certificate.
- Or get the certificate in PFX format along with the password and then import it on the firewall as a local certificate.

Once imported select on the deep inspection SSL profile using 'Protect SSL server' option.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.