Created on
06-19-2024
02:56 AM
Edited on
09-16-2025
10:12 PM
By
Jean-Philippe_P
Description | This article describes how to fix a server's certificate chain when it is shown as 'Incomplete' on a Qualys SSL scan. |
Scope | FortiGate. |
Solution |
When the server's certificate chain is incomplete, it appears on top of the scan and also under the section: 'Additional Certificates' (if supplied), as below:
This happens when the server certificate is missing on the FortiGate. Either upload the server certificate if having already one, or create a CSR on FortiGate, complete the CA signing process, and upload it.
To fix the issue, the intermediate certificate should be imported into the FortiGate. If using a third-party certificate, this is probably included in the certificate bundle from the CA.
Once confirmed, import this as a 'CA Certificate' on the FortiGate. If this is used for SSLVPN, be careful! It will disconnect all connected users
At this point, the full SSL chain should be present on the FortiGate. If there are still issues, check the following:
After checking and fixing this, the new intermediate certificate, along with the end entity, needs to be re-imported into the FortiGate certificate store.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.