Skip to main content
srahmat
Staff
Staff
July 2, 2025

Troubleshooting Tip: How to troubleshoot error 'certificate verify failed: unable to get local issuer certificate' when using LDAPS

  • July 2, 2025
  • 0 replies
  • 670 views
Description This article describes how to troubleshoot the error 'certificate verify failed: unable to get local issuer certificate' when testing login using LDAPS. 
Scope FortiSandbox.
Solution

When configuring the LDAP Servers and enabling secure connection using LDAPS, it shows the error as below.

 

image.png

 

Test login without a secure connection, showing connection status 'Login test success'. The above error means FortiSandbox is unable to verify the LDAP server certificate.

 

To solve this issue, upload the Root CA certificate for the LDAP server in the FortiSandbox and select the uploaded CA certificate in the LDAP Servers setting under the CA Certificate section.

 

image.png

 

In case the certificate has a Sub-CA as part of the certificate chain, user will need to create a bundle of both Root CA and Sub CA and upload them to FortiSandbox and select the bundle certificate in the LDAP server settings. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!