Description | This article describes solutions on how to fix the certificate warning message 'The Certificate Issuer for this site is Untrusted or unknown.’ in FortiClient VPN when a self-signed certificate such as the Fortinet Factory default built-in certificate is used for SSL VPN in FortiGate. |
Scope | FortiGate, FortiClient. |
Solution |
When a self-signed certificate such as the Fortinet Factory built-in certificate is used in SSL VPN, the behavior is expected. Since the certificate is not trusted by the client endpoint, the certificate warning message appears. Unless the Root CA or Intermediate CA is installed in the Trusted Root Certificate Authorities of each SSL VPN client, the certificate error prompts.
To fix the certificate warning error:
This alert may also show up when FortiGate has a valid certificate but has been replaced with a new certificate due to the certificate expiring soon. After the certificate replacement, certain FortiClient versions, including v7.2.0 -> v7.2.8 and v7.4.0-> v7.4.2, may show this error. To solve this issue, FortiClient or the operating system needs to be rebooted. Upgrading to v7.2.9 and v7.4.3 and higher is recommended to avoid this problem.
Note:
For licensed FortiClient managed by the FortiEMS server, go to Endpoint Profiles -> System Settings -> Choose the Profile (Default or Custom), then look for Endpoint Control, set the 'Invalid Certificate Action' to 'Allow', and then select 'Save'.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.