Skip to main content
FortiHelp
New Member
May 13, 2024
Question

FortiClient webserver certificate not secure

  • May 13, 2024
  • 3 replies
  • 1909 views

Dears ,

 

How I can solve this issue?

 

ss.jpg

 

3 replies

ozkanaltas
Valued Contributor III
May 13, 2024

Hello @FortiHelp ,

 

If you install a certificate compatible with fqdn or IP address this warning will disappear. 

 

https://docs.fortinet.com/document/forticlient/7.2.4/ems-administration-guide/917193/adding-an-ssl-certificate-to-forticlient-ems

FortiHelp
FortiHelpAuthor
New Member
May 13, 2024

Dear ozkanaltas ,

 

Many thanks for your kind response. On the EMS server, there are two certificates: one for the web server and the second for the endpoint certificate. I have built a local certificate using OpenSSL and used it for the endpoint control certificate. I have a problem with the webserver certificate.

 

This Photo to understand me better

sss.jpg

 

Thank you

 

ozkanaltas
Valued Contributor III
May 13, 2024

Hello @FortiHelp,

 

First certificate built-in certificate. Because of that, this can't be compatible with ems fqdn. 

 

You need to configure a new fqdn to FortiClient EMS on the Settings page. After that, you need to upload a certificate compatible with this fqdn. Or you can use lets encrypt for this operation. 

 

https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-Troubleshooting-and-Resolving-the-SSL/ta-p/276359

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-EMS-certificate-not-trusted-with-customized/ta-p/240087

 

 

If you don't want to use fqdn instead of IP. You can ignore this warning. 

 

image.png

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!