Skip to main content
ipranger
New Member
July 5, 2020
Question

SSL Inspection question about the Option "Allow Invalid SSL Certificates"

  • July 5, 2020
  • 1 reply
  • 8148 views

Hello all, 

 

i'am using here FortiOS 6.2.4 with deepinspection in Flow and Proxy based mode. A few weeks ago the great event was where there were problems with wrong or broken SSL certificates. Since then I have had problems with websites again and again.

 

For example "logoix.com". If i call the site i get an proxy error in flowbased mode. In proxybased  mode i get an error with an invalid ssl certificate. And there are a lot of site more. Normal sides, trusted sites. 

 

So if i check the box "Allow Invalid SSL Certificates" all websites work as usual. So what does it really mean? Becaues if i have a look at the certificate in the webbrowser, it look like ok. 

 

I've also read this:

https://docs.fortinet.com/document/fortigate/6.0.0/handbook/24449/ssl-ssh-inspection

https://kb.fortinet.com/kb/documentLink.do?externalID=FD40530

 

Thanks and best regards :)

    1 reply

    ipranger
    iprangerAuthor
    New Member
    July 6, 2020