Fortigate IPS and https traffic - don't want browsers having to load fortigate certs
I saw this documentation describing how fortigate IPS can handle SSL traffic for deep content inspection:
"......In this schema, is clear that the SSL/TLS handshake is interrupted, and the FortiGate is required to present a certificate for the URL requested by the real client. This certificate is signed by the FortiGate itself. ............. But is needed to be clear that the Full SSL Inspection the certificate used to sign those sites (by default SSL_Proxy_Inspection into the FortiGate) is needed to be recognized as a valid CA. Otherwise, the warning message will be shown everytime an SSL/TLS connection is made. This certificate (SSL_Proxy_Inspection) must be installed in each PC to be used by their Operating System and/or for browsers/applications (Mozilla Firefox or Java JRE) which has its own Certificate repository." I am surprised that the fortigate can't load the cert and private key for our domain and make this appear as if the ssl connection from the client is to our domain(s), i.e. no need for client to load a cert signed by fortigate. Loading signed fortigate certs into browsers is not an option
