Skip to main content
damianhlozano
Explorer II
August 25, 2022
Solved

Use a web server certificate for deep inspection

  • August 25, 2022
  • 4 replies
  • 2408 views

Hello team!!!

 

Just a basic question

We have a third party certificate issued from a trusteed certificate authority, for our web server.

Is it possible to use the same certificate for doing deep inspection in outgoing fortigate policies?  Is there any requirement for this certificate to work?

What are the steps to import this certificate into a Fortigate in 7.2.1 ?

 

Thanks in advance.

Regards,

Damián

 

Best answer by abelio

damianhlozano wrote:

Is it possible to use the same certificate for doing deep inspection in outgoing fortigate policies?  Is there any requirement for this certificate to work?

Hi

Unfortunately not, you can't use it do that (no commercial isssued certificates can´t I guess)

For deep inspection your certificate must have attribute CA=TRUE or KeyUsage=KeyCertSign

That certificate allows your FGT to issue certificates (and private keys) on the flight.

 

4 replies

abelio
SuperUser
abelioAnswer
SuperUser
August 25, 2022

damianhlozano wrote:

Is it possible to use the same certificate for doing deep inspection in outgoing fortigate policies?  Is there any requirement for this certificate to work?

Hi

Unfortunately not, you can't use it do that (no commercial isssued certificates can´t I guess)

For deep inspection your certificate must have attribute CA=TRUE or KeyUsage=KeyCertSign

That certificate allows your FGT to issue certificates (and private keys) on the flight.

 

kcheng
Staff & Editor
Staff & Editor
August 26, 2022

Hi @damianhlozano 

 

Just like the fact mentioned by abelio, you can't use a web server certificate for deep inspection. The process of deep inspection includes decryption and re-encryption of the packet post content scanning. Hence, it is necessary to equip the certificate with a subCA attribute. You may refer to the documents below for the explanation and steps to generate the certificate if required:

https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/605938/why-you-should-use-ssl-inspection

https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/680736/microsoft-ca-deep-packet-inspection

damianhlozano
Explorer II
August 26, 2022

Thanks for the information guys!!!

 

sw2090
SuperUser
SuperUser
August 26, 2022

that's also the reason why no commercial certs can be used. There is seemingly no commerical CA out there that would issue you a sub-ca certificate :)

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.