Skip to main content
John125478
New Member
December 7, 2018
Question

ssl inspection strips intermediate certificate

  • December 7, 2018
  • 1 reply
  • 6026 views

Hello,

I combined my web server domain certificate with intermediate certificate

[size="1"]

-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
[/size]

to have full certification path. ssllabs.com gives website A rating.

Then I uploaded combined certificate to FortiGate 300E (v6.0.2 build0163 (GA)) System>Certificates>Import>Local CA> Certificate.

I created SSL inspection profile with that combined certificate (Protecting SSL Server, HTTPS 443) and applied this profile to my web server IPv4 Policy SSL inspection.

Now ssllabs.com gives rating B, because certificate chain is incomplete (intermediate certificate is missing). I downloaded certificate from FortiGate and confirmed that intermediate certificate was striped.

Any advice how to keep intermediate certificate when doing ssl inspection with FortiGate?

 

    1 reply

    John125478
    New Member
    December 14, 2018

    SOLUTION:

    separately import the intermediate certificate, make sure that intermediate CA is under the External CA certificates.

    https://kb.fortinet.com/k...ateId=1%200%2057588943