| Description | 
 This article explains how to resolve an issue where FortiGate presents the wrong digital certificate when using the new Sectigo cross-signed certificate chain.  | 
| Scope | 
 FortiGate v7.2 (all supported builds).  | 
| Solution | 
 Problem: Sectigo recently began issuing certificates with a new trust chain. When these certificates are imported into the FortiGate certificate store, the device may not serve the correct intermediate certificate in the certificate chain under certain configurations. This issue is observed specifically when: 
 As a result, FortiGate may present an unexpected or incorrect intermediate certificate from the chain. 
 Workaround: To avoid this issue, apply the following workaround: 
  | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.