| Description | This article describes how to troubleshoot and fix Apache service failures due to a weak Certificate signature algorithm or other missing certificate requirements. |
| Scope | FortiNAC-F, FortiNAC. |
| Solution |
FortiNAC uses Apache service for the portal, and Apache relies on the OpenSSL configuration for certificate requirements. FortiNAC has OpenSSL 3.0, and OpenSSL has multiple security levels. Currently, FortiNAC uses OpenSSL Security Level 1. OpenSSL 3.0 Security Level 1 requirements can be found in the document below.
[Sat May 03 10:58:48.010772 2025] [ssl:emerg] [pid 170240:tid 140000143325056] AH02562: Failed to configure certificate localhost:443:0 (with chain), check /bsc/siteConfiguration/apache_ssl/server.crt
As shown below, in this example, the FortiNAC Portal has a certificate that has a signature algorithm of SHA1. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.