| Description | This article describes how to resolve a scenario where a PKCS12 / PFX Certificate uploaded does not include the full certificate chain. |
| Scope | FortiGate v7.x.x+ |
| Solution |
When uploading a .pfx or .p12 certificate bundle onto the firewall, it will not upload the full chain of certificates. This can cause issues if the full chain is required.
It was necessary to add the ‘-legacy’ flag as this particular cert is using a legacy encryption method. The first certificate is generally the one already included on the firewall. If only seeing one cert, the intermediate certs were not included in this bundle. The rest of the output will show all the included certificates in the bundle. Copy and paste these into new .cer files, then import them into the firewall as ‘CA certificates’.
The firewall will use these certs as a chain while presenting them to the client. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.