FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
RBA
Staff
Staff
Article Id 390020
Description This article describes how to fix the connectivity issue when correct private CA certificate is imported however connectivity still fails.
Scope FortiGate.
Solution

Sniffer on the FortiGate would show Alert (Level: Fatal, Description: Certificate Expired) even though correct private CA is imported.

 

Screenshot 2025-04-30 195639.png

 

CA certificate imported into the FortiGate shows the valid expiry date.

 

1_(3) (1).png

 

Certificates can be exported from the packet capture by following this article: Technical Tip: Extracting certificates from SSL/TLS handshake packet capture 

 

Verify the certificate presented by the server (Issued-To):

 

cert123.png

 

 

The validity has expired, hence the connection fails. The certificate would have to be renewed to fix the issue. 

 

Note:

The connection would work fine when LDAPS is enabled; however, when the certificate is enabled issue would pop up.

This is due to server integrity check, which would be enabled by default whenthe  certificate is enabled.

Contributors