Skip to main content
sw2090
SuperUser
SuperUser
September 7, 2020
Question

Is SSL Deep Inspection screwing up the certification path?

  • September 7, 2020
  • 2 replies
  • 3603 views

I just ran into this.

 

I have https://dealerportal.piaggiogroup.com

If I open this in Browser without Deep Inspection enabled and look into the certification path I see:

 

DigiCert => DigiCert SHA2 Secure Server CA => dealerportal.piaggiogroup.com

 

If I do the same with Deep Inspection enabled I see:

 

<mycompany CA> => <suboridinary CA of company CAused by Deep Inspection> => dealerportal.piaggiogroup.com.

DigiCert plus the following intermediate CA seem to be gone

My Browser then complains that the certificate of dealerportal.piaggiogroup.com does not have a valid digital sigature...

 

Did anyone else encounter this to?

I also openend a ticket with TAC on this.

 

Greetings

Sebastian

    2 replies

    sw2090
    SuperUser
    sw2090Author
    SuperUser
    September 10, 2020

    To give an update:

     

    In my test environment here at HQ it does not. But it did on productive FGT.

    Still investigating on...

    mcdaniels
    New Member
    October 7, 2020

    And you do exactly the same in your test environment?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!