| Description | This article describes how to allow Expired/Invalid Certificates in firewall ssl-ssh-profile. |
| Scope |
FortiGate. |
| Solution |
v6.0.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> set allow-invalid-server-cert [enable | disable] end
v6.2.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> config <ssl|https|ftps|imaps|pop3s|smtps> set invalid-server-cert [allow|block] end
v6.4 and v7.0.
config firewall ssl-ssh-profile edit <SSL-SSH-PROFILE-NAME> config <ssl|https|ftps|imaps|pop3s|smtps> set expired-server-cert [allow|block|ignore] end
Configuration requirements.
Configuration Example to block expired and revoked certificates (showing only related elements).
SSL/SSH certificate:
F2 (Clone of deep-in~ion) # show config https Firewall Policy:
config firewall policy |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.