Skip to main content
AlexFerenX
Visitor III
January 10, 2025
Question

Clarification on the certificate used for "Protecting an SSL server"

  • January 10, 2025
  • 18 replies
  • 3716 views

Hi!

I seek clarification on the feature Protecting an SSL server (aka. firewall ssl-ssh-profile's server-cert-mode is "replace").

Is it mandatory that the specified "Server certificate" (in SSL/SSH Inspection Profile) be identical to the actual server certificate - yes or no?

Thanks!

 

PS. Plausible example where I'd prefer that "Server certificate" is NOT identical to actual server certificate is when I prefer it be a wildcard certificate (thus valid for multiple servers within same domain).

18 replies

dingjerry_FTNT
Staff
Staff
January 10, 2025

Hi @AlexFerenX .

 

The quick, simple answer is NO.

 

The specified "Server certificate" (I would like to call it CA Certificate) (in SSL/SSH Inspection Profile) is the one FGT uses to decrypt and re-encrypt the packets doing MITM inspection. 

 

So if the client does not have this certificate installed, the client will get a certificate warning.  If the client does have the certificate installed in the browser, the client will not get a certificate warning.

 

BTW, this certificate has to be a "CA:TRUE" certificate. I would say, that none of the public certificate authorities (like Verisign, GoDaddy etc) will sell this type of certificate.

 

However, you can use your own company CA (i.e. Microsoft CA server) or OpenSSL to generate this type of CA certificate and it is also self-signed.  And install the root CA into the clients to trust this CA certificate to avoid a certificate warning.

 

 

AlexFerenX
Visitor III
January 10, 2025

Hi @dingjerry_FTNT 

 

> So if the client does not have this certificate installed, the client will get a certificate warning. If the client does have the certificate installed in the browser, the client will not get a certificate warning.

 

The client doesn't need to have anything in the browser - the certificate installed in ssh-ssl-profile's "server-cert" will be a public certificate in the same way that the actual server certificate is.

 

My question is about "Protecting SSL Server" feature, not "Multiple Clients Connecting to Multiple Servers" feature - are you sure you're not confusing the two?

 

Thanks!

dingjerry_FTNT
Staff
Staff
January 10, 2025

Hi @AlexFerenX ,

 

Sorry, my bad. I made a mistake.

 

Yes, you have to use the same server certificate.  Otherwise, the CA name or the SNI will not be matching to the one that the client wants to access.  If there is a security device doing UTM-like inspection for the client,  the client may get denied.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.