| Description | This article describes how to verify that a certificate is signed by a correct CA. |
| Scope | FortiGate, FortiAuthenticator, and any other devices involve certificate-related verification or authentication. |
| Solution |
It has been a known method to identify whether a certificate has been signed by the correct CA certificate by checking the 'Issued to' and 'Issued by' fields on the certificate's general tab. A CA can be easily identified by observing that the 'issued by' and 'Issued to' fields have the same value. The signed certificate should have the 'issued by' as the name of the CA certificate and 'Issued to' as its own CN value.
But there is a more technical way of verifying a certificate by using OpenSSL. OpenSSL has to be downloaded and installed on the PC/laptop where both certificates are available, or they can be stored in a folder in the respective device. Use site below to download OpenSSL. Linux: Downloads. Windows: Binaries.
Steps to follow:
openssl verify -CAfile <name of the CAfile> < name of the certificate to be verified>
Red: Folder where certificates are located. Purple: OpenSSL command for verify. Yellow: CA certificate. Green: Certificate signed by the CA. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.