Troubleshooting Tip: How to troubleshoot error 'certificate verify failed: unable to get local issuer certificate' when using LDAPS
| Description | This article describes how to troubleshoot the error 'certificate verify failed: unable to get local issuer certificate' when testing login using LDAPS. |
| Scope | FortiSandbox. |
| Solution | When configuring the LDAP Servers and enabling secure connection using LDAPS, it shows the error as below.
Test login without a secure connection, showing connection status 'Login test success'. The above error means FortiSandbox is unable to verify the LDAP server certificate.
To solve this issue, upload the Root CA certificate for the LDAP server in the FortiSandbox and select the uploaded CA certificate in the LDAP Servers setting under the CA Certificate section.
In case the certificate has a Sub-CA as part of the certificate chain, user will need to create a bundle of both Root CA and Sub CA and upload them to FortiSandbox and select the bundle certificate in the LDAP server settings. |


