FortiClient
FortiClient proactively defends against advanced attacks. Its tight integration with the Security Fabric enables policy-based automation to contain threats and control outbreaks. FortiClient is compatible with Fabric-Ready partners to further strengthen enterprises’ security posture.
btan
Staff & Editor
Staff & Editor
Article Id 413801
Description This article describes troubleshooting steps for the 'The highlighted Subject and Issuer values do not match' message that may appear when uploading an SSL cert to FortiClient EMS.
Scope FortiClient EMS v7.2 and v7.4.
Solution

When uploading an SSL cert to FortiClient EMS, it may display a message stating 'The highlighted Subject and Issuer values do not match. Please ensure the certificate chain is valid.':

 

kb-oct2-1.png

 

Note that this is just an informative message: it does not indicate there is any actual error on the SSL certificate.

 

To verify if the certificate chain is valid, access the FortiClient EMS FQDN in web browser, then select the lock icon:

 

kb-oct2-result2.png

 

If it shows 'Certificate is valid', the SSL certificate can be used.

 

If there are errors in the verification above, engage the certificate provider to fix it.

 

After verifying the uploaded SSL certificate is valid, it can be used on FortiClient EMS as a [Webserver certificate] and [Endpoint Control certificate]. Ensure that there is only one FQDN in the [Use FQDN] field.

 

kb-oct2-2.jpeg