Skip to main content
fortinoob
New Member
April 4, 2016
Question

ssl inspection PKI issue - inbound policy (protecting a server)

  • April 4, 2016
  • 1 reply
  • 5018 views

hi all,

so i'm trying to solve this issue for the last few days.

first i have imported my server certificate onto my fortigate unit as local certificate (public+private).

second i activated ssl-inspection profile with the option "protecting a server" which i understand means replace certificate instad of resign

and last i have activated that profile on my inbound traffic (VIP->SERVER HTTPS).

now when someone try to access that certifiace it fails most of the time beacuse it seems the PKI chain is broken.

i also installed the subordiante CA (go daddy g2 CA) on my unit as external ca with the same results.

 

1 reply

fortinoob
fortinoobAuthor
New Member
April 4, 2016

seems i found my problem.

AV on proxy mode (on the same policy) did all the truble.

flow mode works fine.

seems its listed as a bug on 5.4 release notes (bug ID 304432)

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!