Skip to main content
BK_LGW
New Member
July 9, 2020
Question

SSL/SSH Inspection Challenge - Invalid Digital Signature

  • July 9, 2020
  • 8 replies
  • 10223 views

Hello all. I'm experiencing some difficulties with using Web Filtering and SSL Inspection. My test policy has blocked the usual culprits (social media, gambling, porn, etc.) and I have a test machine and user going to the Internet via the policy.  This is what I've done:

- Acquired root and subordinate CA certs from my sub ca server, imported them into FGT as root and sub CAs respectively.

- Created a local CA for the FGT via the Issuing server (my sub ca server)

- Created an SSH/SSL Inspection profile utilizing the local CA object 

- Created a Web Filter profile blocking the usual suspects

- Created policy outlining both the SSL Inspection and Web Filter profiles and made it so only a single user/PC combo hits it

 

Below are some of the issues I'm having with some websites. Others are blocked and show the block page as expected. All HTTPS websites. What am I doing wrong?

8 replies

Dave_Hall
New Member
July 9, 2020

Has the security cert been imported into the browser of the client (test) workstation?

BK_LGW
BK_LGWAuthor
New Member
July 10, 2020

Thank you for your quick reply. The root and sub ca certs were already in the Trusted Root CA and Intermediate CA stores due to AD membership. I manually imported the FGT's local cert into the Intermediate CA store. I've been using MS Edge and Internet Explorer which I believe uses the PC's certificate stores, so yes, it should be seen by the test client.

emnoc
New Member
July 10, 2020

The output clearly says other wise. Is the certificate ( root/subca ) trusted by that machine and browser? Also if is FF it does not use the OS cert-store.

 

Ken Felix

Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!