Skip to main content
hhasny
Staff
Staff
March 10, 2026

Troubleshooting Tip: FortiSASE re-signing as Untrust certificate

  • March 10, 2026
  • 0 replies
  • 183 views
Description This article describes why FortiSASE is re-signing the website with an Untrust certificate.
Scope FortiSASE.
Solution

When accessing websites with deep-inspection is use and, the websites are complaining of a certificate issue even though the CA certificate of Fortinet_CA is installed.

 

website error.png

 

Verify what certificate is presented to the browser. In this case, the Fortinet Untrusted CA is used.

 

untrust certificate.png

 

Usually, this untrust certificate is due to FortiSASE not being able to resolve the FQDN.

Verify FortiSASE is using a working DNS server for DNS resolution.