Skip to main content
nguyenbakhanh
New Member
October 2, 2021
Question

FIX WIN 7: this site's security certificate is not trusted

  • October 2, 2021
  • 4 replies
  • 2734 views

[style="vertical-align: inherit;"][style="vertical-align: inherit;"]FIX WIN 7: this site's security certificate is not trusted: [link]https://youtu.be/0e42USqE-CM[/link][/style][/style]

    4 replies

    nnair
    Staff
    Staff
    May 3, 2023

    Thank you for the post.
    The update that you have shared is not clear, based on the title please check the below link:
    https://community.fortinet.com/t5/FortiGate/Technical-Tip-Untrusted-certificate-warning-in-FortiGate-for/ta-p/189829

    rosatechnocrat
    Explorer III
    May 3, 2023

    Potential causes could be : 

    1> You are using a deep certificate inspection policy ( SSL-SSH Profile) without a proper certificate. 

    2> You are presenting your Fortigate certificate to the user, which might not be trusted in the client as the Root CA is not trusted or Fortigate has a self-signed certificate. 

     

    Solution : Try removing the SSL profile or all UTM features from a particular policy and test the behavior. 

    Subscribe "ROSA Technocrat" on Youtube for Fortinet Videos and Troubleshooting https://www.youtube.com/@rosatechnocrat
    rosatechnocrat
    Explorer III
    May 3, 2023

    You might would like to visit below link if you want to get more details on certificate and SSL Profile. 

     

    https://docs.fortinet.com/document/fortigate/5.4.0/cookbook/329138/preventing-certificate-warnings

    Subscribe "ROSA Technocrat" on Youtube for Fortinet Videos and Troubleshooting https://www.youtube.com/@rosatechnocrat
    rtichkule
    Staff
    Staff
    May 4, 2023

    An error message stating "This site's security certificate is not trusted" may indicate that your FortiGate firewall does not recognize or trust the security certificate for the website you are trying to access.


    This error message could appear for a number of different reasons. The security certificate for the website may have expired or been issued by a Certificate Authority (CA) that is not recognised by your firewall. It's also conceivable that your firewall is preventing the SSL/TLS connection to the website for another reason.

     

    If the padlock is visible in your web browser's address bar, you can accomplish verification by clicking on it to view the certificate's details. Verify the certificate's expiration date and that a reputable CA issued it.

     

    You might need to modify your SSL/TLS inspection settings to enable the connection if your firewall is preventing the SSL/TLS connection to the website. For instructions on how to do this, consult the below documentation for your firewall.

    SSL Inspection | FortiGate / FortiOS 6.2.5 (fortinet.com)