Created on
08-31-2021
02:49 AM
Edited on
03-24-2025
05:49 AM
By
Anthony_E
Description
This article describes how to block invalid and revoked certificates with FortiGate.
Testing can be done with corresponding pages on the badssl site mentioned below.
Scope
All supported FortiOS to date (v7.2.11, v7.4.7, v7.6.2). There is no indication this behavior will change in the future.
Solution
Under the SSL/SSH inspection profile, set 'Block' for 'invalid SSL certificates'.
Related articles:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.