Skip to main content
drinker
New Member
March 10, 2026
Question

Bad certificate from Fortinet

  • March 10, 2026
  • 5 replies
  • 385 views

My two favourite pubs are both owned by the Greene King chain. There is no cellular signal at either of them so I like to use their free wi-fi. Everything works as expected on a public wi-fi except when I browse one particular site I get a warning that someone may be trying to intercept my communications. Only that one site (so far as I know). The site's legitimate certificate from Let's Encrypt is replaced by a fake one which claims to be issued by Fortinet. I would like to know what is going on; am I being snooped on?

5 replies

sw2090
SuperUser
SuperUser
March 10, 2026

Do they have a FortiGate with Deep Packet Inspection in use? If they then used some selfsigned cert (or one of the fortinet built in CAs) this will cause exactly what you got because your Browser/Client cannot verify the thrustworthyness of the certificate issued by the FGT's DPI.

drinker
drinkerAuthor
New Member
March 10, 2026

It's free wi-fi in a pub so I can't know how exactly they operate it.  You are of course correct that rogue certs should be rejected by the browser.

The fake certificate says "Organisation (O) Fortinet" so I thought fair to assume Fortinet might be involved in it somehow. But why choose just one particular website for which to fake the certificate? This does not happen with any other website which I visit on the same wi-fi connection. And more importantly why target me; if I trusted Fortinet's Root CA, which luckily I don't, then I would successfully have been MITMd.

I should say that there is no evidence that Fortinet has anything at all to do with this. However considering they are in this line of business I thought it was reasonable to start by asking for ideas in this place.

sw2090
SuperUser
SuperUser
March 10, 2026

what does it say as Comon Name (CN)?

 

drinker
drinkerAuthor
New Member
March 10, 2026

Here is screenshot
Fortinet_cert.jpeg

sw2090
SuperUser
SuperUser
March 11, 2026

ah yeah I see. That indeed looks like Deep Packet Inspection on a FGT. The Issuer Common Name is the Serial of the FortiGate involved. So looks like they run a FortiGate 40F and have DPI activated one some policy that matches dosbods.com...

drinker
drinkerAuthor
New Member
May 21, 2026

The service provider silently fixed it. I never found out why they targeted our site. Thanks for advice.and help.