Scan is coming back with failures on the follow, these all relate to either the Fortinet_CA or the Fortinet_Sub_CA. I've already updated my certificate for Administration as well as my SSL VPN certificate with a valid certificate. How can I go about updating the items below? Being they appear to be Root CAs I don't see them "attached" anywhere. When I look at Certificates in the unit they show up under Remote CA Certificates. Basically it doesn't like the length of these or the fact that they are showing as self-signed. I'm assuming if I remove these it will cause issues with other Fortinet Certificates, best option to proceed?
SSL Certificate - Invalid Maximum Validity Date Detected 1003 / tcp over ssl
SSL Certificate - Signature Verification Failed Vulnerability1003 / tcp over ssl
SSL Certificate - Invalid Maximum Validity Date Detected1000 / tcp over ssl
SSL Certificate - Signature Verification Failed Vulnerability1000 / tcp over ssl
SSL Certificate - Self-Signed Certificate1003 / tcp over ssl
SSL Certificate - Self-Signed Certificate 1000 / tcp over ssl
Here are some details from the scan as well
Result
Certificate #0 emailAddress=support@fortinet.com,CN=***,OU=FortiGate,O=Fortinet,L=Sunnyvale,ST=California,C=US ISSUER:_emailAddress=support@fortinet.com,CN=fortinet-subca2001,OU=Certificate_Authority,O=Fortinet,L=Sunnyvale,ST=California,C=US is valid for more than 398 days
Result
Certificate #0 emailAddress=support@fortinet.com,CN=***,OU=FortiGate,O=Fortinet,L=Sunnyvale,ST=California,C=US ISSUER:_emailAddress=support@fortinet.com,CN=fortinet-subca2001,OU=Certificate_Authority,O=Fortinet,L=Sunnyvale,ST=California,C=US self signed certificate in certificate chain
Thanks for your help in advance!