ssl inspection PKI issue - inbound policy (protecting a server)
hi all,
so i'm trying to solve this issue for the last few days.
first i have imported my server certificate onto my fortigate unit as local certificate (public+private).
second i activated ssl-inspection profile with the option "protecting a server" which i understand means replace certificate instad of resign
and last i have activated that profile on my inbound traffic (VIP->SERVER HTTPS).
now when someone try to access that certifiace it fails most of the time beacuse it seems the PKI chain is broken.
i also installed the subordiante CA (go daddy g2 CA) on my unit as external ca with the same results.
