Skip to main content
kphed
New Member
September 30, 2021
Question

WCF SSL Certificate Errors

  • September 30, 2021
  • 5 replies
  • 24759 views

Is anyone suddenly receiving certificate errors?  A large number of customers are reporting certificate errors when browsing exempted/trusted domains.  The SSL logs in the GUI show, "Server certificate blocked".

    5 replies

    recha
    New Member
    September 30, 2021

    Hello, 

     

    I confirm, since 4:01 PM, i guess it's linked to the identrust expiration...

    If you bypass the web filtering, no issue... but it's not a solution....

     

    for information:

    https://scotthelme.co.uk/...t-old-root-expiration/

    Brimstar
    New Member
    September 30, 2021

    Talked to support.  They've confirmed they're working on it, but it is an issue with the Identrust expiration.  Probably going to turn off the expired cert filter.  I think that's about all we can do for now.

    WesMasterson
    New Member
    September 30, 2021

    I think it has something to do with

     

    DST Root CA X3 that expired today, but I haven't found a work around for it.

    jm75
    New Member
    September 30, 2021

    Hello,

     

    Maybe blocked sites when using a Let's Encrypt certificate?

     

    https://docs.certifytheweb.com/docs/kb/kb-202109-letsencrypt/

    https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/ (site not accessible with this  expired certificate problem)

     

    I don'k know the good solution.

    Defaut SSL/SSH inspection with the default "certificate-inspection" policy blocks the expired certificate.

     

    J.

    Brimstar
    New Member
    September 30, 2021

    I'm almost positive it's an issue with change of Let's Encrypt over to the ISRG certificate.  Every site that was reported blocked that I've reviewed is using a Let's Encrypt certificate.  I've got a case open and I'm waiting on a fix.  In the meantime, I've done the only thing I can by allowing expired certificates so people can continue to work.  Let's Encrypt is too commonly used to simply block any site using them.

    Scott_Seifel
    New Member
    September 30, 2021

    It appears FortiOS 6.4.x is immune to this situation as only our clients with firewalls running FortiOS 6.2 and earlier are affected.  Are any of you seeing the same pattern?

     

    We are going with the allow invalid certs option until Fortinet addresses the issue.

    kaiseal1
    New Member
    September 30, 2021

    No, can't confirm. We face the same problem on 6.4.6/6.4.7

    it_service
    New Member
    October 2, 2021

    Issue on 6.4.5 temporarily resolved by following workaround: 1: verify cert bundle is v28 -> diag autoupdate versions -> execute update-now 2: apply DNS blackhole workaround: -> config system dns-database -> edit "1" -> set domain "identrust.com" -> config dns-entry -> edit 1 -> set hostname "apps" -> set ip 127.0.0.1 -> next -> end 3a: flow-mode: -> diag ips share clear cert_verify_cache 3b: proxy-mode: ->:diag test app wad 99

    Lucascat
    New Member
    October 27, 2021

    What about a definitive solution?