SSL Certificate Inspection, CA certificate and www.amazon.com
Dear all,
I do not clearly understand the role of the CA (self-signed) certificate in regards of the SSL Certificate Inspection feature. If I understand well, in SSL Certificat Inspection mode, the FortiGate "sees" the server certificate, and is assessing the relationship between the requested URL and the subject of the certificate.
1) so why the CA Certificate (self-signed) is required ?
2) actually, it appears that when I established an initial TLS session with, lets say, www.amazon.com, the CA (self-signed) certificate is given to the client. Why does this happen ?
3) I notice that TLS sessions that follow with www.amazon.com, the official (Amazon's) certificate is given to the server.
I clearly missed something, but unfortunately I've been unable to find the answer in my reading (official documentation, this site).
The real problem comes with servers that do certificate pinning, as Facebook or Twitter, or Gmail... because the client refuse to proceed on establishing the TLS session.
Thank you for your help.
Claude
