Skip to main content
rezafathi
Explorer III
April 30, 2025
Question

full isnpection problem

  • April 30, 2025
  • 6 replies
  • 4443 views

Hi

 

I have updated my FGT 200F to 7.6.3 version. from now on, full ssl inspection has many problems. it shows certificate error for some websites which was working well before and some times it bypasses all websites automatically. here is the error message for chatgpt :   please help

 

net::ERR_CERT_DATE_INVALID Subject: chatgpt.com Issuer: FG200FT9044229 Expires on: Apr 30, 2025 Current date: Apr 30, 2025 PEM encoded chain: -----BEGIN CERTIFICATE----- MIIEIDCCAwigAwIBAgIUdrj1VYAKb+FPzB4q2HANTQTfVcIwDQYJKoZIhvcNAQEL BQAwgakxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRIwEAYDVQQH DAlTdW5ueXZhbGUxETAPBgNVBAoMCEZvcnRpbmV0MR4wHAYDVQQLDBVDZXJ0aWZp Y2F0ZSBBdXRob3JpdHkxGTAXBgNVBAMMEEZHMjAwRlQ5MjI5MjA1ODExIzAhBgkq hkiG9w0BCQEWFHN1cHBvcnRAZm9ydGluZXQuY29tMB4XDTI1MDQwMzAwMTYwNFoX DTI1MDQzMDA1NDY1MVowFjEUMBIGA1UEAxMLY2hhdGdwdC5jb20wWTATBgcqhkjO PQIBBggqhkjOPQMBBwNCAARSTlz4/3zd7PcHph2Iwh0IgKNBtZHPkGl1IovCE4Qq BDlfa9Kx3S++x0WXdGBCPmx8bh9xp4/SlgeWq8kMUl0So4IBmzCCAZcwDgYDVR0P AQH/BAQDAgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHQYD VR0OBBYEFOzB9eNk6df5NLKSqor+ttyRhjwrMCUGA1UdEQQeMByCC2NoYXRncHQu Y29tgg0qLmNoYXRncHQuY29tMBMGA1UdIAQMMAowCAYGZ4EMAQIBMIIBBQYKKwYB BAHWeQIEAgSB9gSB8wDxAHYAEvFONL1TckyEBhnDjz96E/jntWKHiJxtMAWE6+WG JjoAAAGV+Tg1UgAABAMARzBFAiEA0kPEvGJh67vllRBPfhhGLm784moI8AvkKKBG yU/DQRoCIHQuO8SLAytnkdxWERMU+rr3fDfg+O7klDYp+NYH76M1AHcAouMK5EXv va2bfjjtR2d3U9eCW4SU1yteGyzEuVCkR+cAAAGV+Tg1XgAABAMASDBGAiEAp+lp 4JFNQSaP4ZjX3qpB/gAaV9RvtzYqO1VcY9J/5foCIQDlurDn4NJAmxHzwvmSlqJq /Wek3+rD8+SXT0e1sk/uvjANBgkqhkiG9w0BAQsFAAOCAQEAePIKm7gD8gPhEa4D l9R+7txwY81YuENqd11ZNM1c4Hmb0e7xOKJKoaxyY27k8cjNjVG8A4EISAvg4t7Q VgZg679TLxZadwY9atiaFvw2PDr4baWY+GzBVYCWti+oFNJsCR/6HpSvuXGlms6J swYwLZKoNdYrCu9NFoH3nzEsXsF+nGa75Lv1LNikS+Od/rE9Qm5vakM6N6vp5BBJ LZiTPSuH0xiQlNemU4WLysKSfor+E5iHNpE7igOQgqRNdAqUsNx291eG82yFf6Co eTR8x1e2OPVyRyM1v4zarcY/bfikxL2ueSuyoRxMPNxPvimBzFHW0IqLehGwF6Ec en11vQ== -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIID5jCCAs6gAwIBAgIIS24Y0WDo0oswDQYJKoZIhvcNAQELBQAwgakxCzAJBgNV BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRIwEAYDVQQHDAlTdW5ueXZhbGUx ETAPBgNVBAoMCEZvcnRpbmV0MR4wHAYDVQQLDBVDZXJ0aWZpY2F0ZSBBdXRob3Jp dHkxGTAXBgNVBAMMEEZHMjAwRlQ5MjI5MjA1ODExIzAhBgkqhkiG9w0BCQEWFHN1 cHBvcnRAZm9ydGluZXQuY29tMB4XDTIzMTEyNzEzMzExMVoXDTMzMTEyNzEzMzEx MVowgakxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRIwEAYDVQQH DAlTdW5ueXZhbGUxETAPBgNVBAoMCEZvcnRpbmV0MR4wHAYDVQQLDBVDZXJ0aWZp Y2F0ZSBBdXRob3JpdHkxGTAXBgNVBAMMEEZHMjAwRlQ5MjI5MjA1ODExIzAhBgkq hkiG9w0BCQEWFHN1cHBvcnRAZm9ydGluZXQuY29tMIIBIjANBgkqhkiG9w0BAQEF AAOCAQ8AMIIBCgKCAQEA3GT3j3iaTMzFWO1rF+Nu6bUZD4F4d8TYNKa2QcOnsGNx VdSvBI8gh4pR/LNJ1YKSlWLCjIf9Eg0KQMcx77eI3+onkO0erV2vZRrdxlnDZ09t Tk6IYLjOge5hhArLlWbCxYQGhf6E3K8lp+u8hsBN9rlZMvpsX+RgNcbgp8Rh3iKR sSyWRIBB7uyJADgStiiopquaVPdATsXZRfknj9ycFbSQzyVF+UxI5Ih2GNhMAVZX u5r8xUhgmU1tFkkKP2blEZvwSmMmdTSWdgNECrwMbyrqNXHgxUVEWjVvLR7w2kUq 2OV37mxb+lm8Ikq20IeuJJzdvX+W2jVItNk2Y0hCZQIDAQABoxAwDjAMBgNVHRME BTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCw9An+o5jlORumuEbzOj3Q+47SnsoN VuJd0gXw9Y83DWKDhfhE5RE9/lnd/6+NGiK2n5NopO1ie/TTsVby/F/h69BZl1jN dl55TjMy/Ef3R4tpxZ1BRRROpc8yNd0NeEKcfnVqzC4EkvfGDWXATaNid2mEDmZx Rfno9jTyBia1O7CBOyQB9XNXyJeZQyk2S0jU23t1e4KdeJjBIEv5SegyKJcB/HJG R+221AoJzrxi/VcvFXkqEhqgloS2Uz3K1XqmNLiQOFbOvPErD3j9x5DrOHuRx2XY eIQsQBLmqtQLFPJ+wfKGYYOUwZAzA68ZrCvmU9H+xUBNm6zV6UimKfl1 -----END CERTIFICATE----- Certificate Transparency: SCT Google 'Argon2025h2' log (Embedded in certificate, Invalid signature) SCT Let's Encrypt 'Oak2025h1' (Embedded in certificate, Invalid signature)

6 replies

funkylicious
SuperUser
SuperUser
April 30, 2025

hi,

it may seem that your certificate has expired and you might need to renew it.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Renew-Certificate-Expired-on-FortiGate/ta-p/220901 

"jack of all trades, master of none"
rezafathi
rezafathiAuthor
Explorer III
April 30, 2025

Hi

No it did not expire.

Screenshot 2025-04-30 105452.png

funkylicious
SuperUser
SuperUser
April 30, 2025

your logs and and certificate it self may say something else.

Screenshot 2025-04-30 at 10.31.16.png

Valid to : Wednesday, April 30, 2025 8:46:51 AM

"jack of all trades, master of none"
rezafathi
rezafathiAuthor
Explorer III
April 30, 2025

all users have this problem. as I said before this error is for some websites .and no i do not have any ssl error log

Blemflarks
New Member
April 30, 2025

The 10 year self signed certificate is not the problem here. The fortigate is re-creating the actual certs wrong, they have a shorter "Valid until" date. If this date then is reached, you will see the errors.
We see the same problem, and have a case open right now with tech support.

Changing the 10 year self signed cert did not fix the issue.

rezafathi
rezafathiAuthor
Explorer III
April 30, 2025

hi

 

what should i do now? please keep me updated about the case.

ChriMaas
New Member
May 2, 2025

I can confirm this issue, it is happening to me as well. My CA is still valid until 2033. However, the Fortigate does not renew Certificates for some websites after the first connect. Since those ssl inspection certificates are valid for 5 days, the issue takes some time to build up.

 

A diag test application wad 99 fixes the issue.

Blemflarks
New Member
May 2, 2025

Could you elaborate on the 

diag test application wad 99

?

I had the impression that any "diag" command is read only, and only "config" or "execute" can change stuff. Was the command provided by the support team?

 

 

ChriMaas
New Member
May 9, 2025

Usually you are correct. However, there are some exceptions like this one.
The command restarts the WAD Daemon, which is the Web Proxy process of FortiOS.

It is described here: https://community.fortinet.com/t5/FortiProxy/Technical-Tip-How-to-restart-the-WAD-process/ta-p/212789 

and in greater detail here: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Overview-of-WAD-process-structure/ta-p/197183

mriswan
Staff
Staff
May 28, 2025

This issue relates to the certificate manager feature change introduced in v7.6. The new option 'resigned-short-lived-certificate' feature is not working properly with certificate cache-timeout.
Please follow below KB for workaround:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-ERR-CERT-DATE-INVALID-error-for/ta-p/393925

GenesisTechhub
New Member
May 29, 2025

We are having the exact same issue as well. Has there been any response from TAC on this?

mriswan
Staff
Staff
May 29, 2025

Hi,
If you FGT is on v7.6, This issue might be related to the certificate manager feature change introduced in v7.6. The new option 'resigned-short-lived-certificate' feature is not working properly with certificate cache-timeout.

Please follow below KB for workaround:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-ERR-CERT-DATE-INVALID-error-for/ta-p/393925