Skip to main content
3RR0R
New Member
March 11, 2024
Question

SSL Certificates Error for Protecting SSL Server

  • March 11, 2024
  • 20 replies
  • 11211 views

Hello

I'm trying to set up a SSL Inspection Profile for a Server behind our Fortigate but as soon as I activate the SSL Profile I get an error for the Website that it's not been trusted. SSL Inspection Options is set to Protecting SSL Server.

If I activate the SSL Profile on the Policy and check on https://www.digicert.com/help/ I get following error:

"The Certificate is not issued by DigiCert, GeoTrust, Thawte, or RapidSSL" and the Serial Number which is shown for the Certificate I can't find under Certificates

I uploaded the Wildcard Certificate with Private Key to the Local Certificate and I can see it there. I also see the Intermediate Cert in the Remote CA Cerificate section. Do I have to upload the Root Cert as Remote Certificate to work or what could be the Problem?

I would appreciate your help!

20 replies

AEK
SuperUser
SuperUser
March 11, 2024

Hi

  • In your SSL profile, did you select the right certificate as "Server Certificate"?
  • When you get certificate warning on your browser, click on certificate information, do you see DigiCert as issuer name / verified by?
  • Do you have the whole certificate chain in the certificate file that you installed on the you FortiGate? (you can check the certificate properties in menu System > Certificates)
  • Have you tried with a client other than Android? (Windows or Linux PC)
AEK
3RR0R
3RR0RAuthor
New Member
March 11, 2024

Hi
Yes I did select the right Certificate in the Profile.
I also tried with different Browsers. In the Certificate Viewer on the Browser it says that the Certificate was issued by Fortinet. Even though I  selected the Server Certificate I uploaded.

 

I uploaded the Wildcard Certificate by itself. Do I have to upload the whole Certificate Chain in one File to the Fortigate?

Thank you

AEK
SuperUser
SuperUser
March 11, 2024

Hi

Then this is not a certificate chain issue. If your browser said it is using Fortinet issued certificate then the traffic is probably handled by a policy that is not using the right SSL profile.

  • Ensure that the right policy is matching the incoming traffic (check in traffic log)
  • When doing some change try from a private browser window to ensure that it doesn't use the cache

On the other hand (but this is not the cause of your issue), as per my knowledge, usually public certificates are provided with the whole certificate chain in one file. Just check your certificate properties under FGT menu/ System > Certificates). Otherwise it is better to upload it since not all client types accept a certificate without the whole chain.

AEK
orio76
New Member
May 13, 2024

hey,

 

Do you have the "set server-cert-mode replace"? this might be your problem.

Best regards

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!