FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Ylli_Seitaj
Staff
Staff
Article Id 321178
Description This article describes how to fix a server's certificate chain when it is shown as 'Incomplete' on a Qualys SSL scan
Scope FortiGate.
Solution 

When the server's certificate chain is incomplete, it appears on top of the scan and also under the section: 'Additional Certificates' (if supplied), as below:

 

This happens when the server certificate is missing on the FortiGate. Either upload the server certificate if having already one, or create a CSR on FortiGate, complete the CA signing process and upload it.

 

Screenshot_1.png

 

Screenshot_2.png

 

To fix the issue, upload the server certificate again or generate a new CSR, depending on how the certificate is created.

To delete the expired or existing certificate, go to System -> Certificate and select the certificate to delete.

To upload the certificate again or to generate a new CSR, select 'Create/Import' and choose 'Certificate' or 'Generate CSR', as below:

Screenshot_3.png

 

For the next steps to upload the certificate or to generate a new CSR, follow the below document:

If the certificate is signed by a third-party certificate issuer(Ex. GoDaddy, DigiCert etc.) and the server certificate chain is showing incomplete it has to be fixed by the certificate issuer and this is not a Fortinet issue.

The following facts are required to be checked:

  • If the certificate is expired or not.
  • If the certificate is revoked or not.
  • The incorrect intermediate certificate for the server or end-entity certificate.

After checking and fixing this the new intermediate certificate along with the end entity needs to be re-imported into the FortiGate certificate store.


Related article:

Uploading a certificate using the GUI