FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Dongfang_Li_FTNT
Article Id 216971
Description

This article describes that when a user connects to FortiGate GUI using HTTPS, the web page displays the certificate error: ERR_CERT_COMMON_NAME_INVALID.

Scope FortiGate all firmware versions.
Solution

The following certificate error is seen.

 

Dongfang_Li_FTNT_0-1657142449240.png

 

The Common Name represents a server name protected by the SSL certificate.

 

The certificate is valid only if the requested hostname matches the certificate's common name.

 

Check the Certificate, it is issued to *****.com:

 

 

Dongfang_Li_FTNT_1-1657142449246.png

 

 

The user connects to the IP address https://x.x.x.x. The certificate's common name is *****.com, they don’t match.

 

The certificate should be issued to the IP address x.x.x.x, or the user should connect to the URL *****.com.

 

To use the IP address when connect, create a new CSR in FortiGate, in Subject Information, ID Type, enable 'Host IP', and put IP x.x.x.x.

 

Complete the CSR, download it, have it signed and import it back to FortiGate.

 

Assign it to the admin access:

 

# config system global

set admin-server-cert <certificate_name>

 end

 

References:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-assign-a-SSL-certificate-for-remote...

https://docs.fortinet.com/document/fortigate/6.0.0/cookbook/645186/generating-a-csr-on-a-fortigate

Contributors