Created on
‎06-19-2024
02:56 AM
Edited on
‎02-01-2025
05:01 AM
By
Anthony_E
Description | This article describes how to fix a server's certificate chain when it is shown as 'Incomplete' on a Qualys SSL scan |
Scope | FortiGate. |
Solution |
When the server's certificate chain is incomplete, it appears on top of the scan and also under the section: 'Additional Certificates' (if supplied), as below:
This happens when the server certificate is missing on the FortiGate. Either upload the server certificate if having already one, or create a CSR on FortiGate, complete the CA signing process and upload it.
To fix the issue, upload the server certificate again or generate a new CSR, depending on how the certificate is created. To delete the expired or existing certificate, go to System -> Certificate and select the certificate to delete. To upload the certificate again or to generate a new CSR, select 'Create/Import' and choose 'Certificate' or 'Generate CSR', as below:
For the next steps to upload the certificate or to generate a new CSR, follow the below document:
After checking and fixing this the new intermediate certificate along with the end entity needs to be re-imported into the FortiGate certificate store.
|