Hello,
ave a FortiSIEM setup with a supervisor, worker, and collector. I encountered an issue while deploying an SSL certificate to replace the default Fortinet certificate. I have three certificate files: server.pem, key.pem, and trustrootCa.crt. I initially deployed these certificates in /etc/httpd/conf.d/ssl.conf as follows:
The SSL certificate was deployed on all servers using this configuration. When running curl -vv https://FQDN from the collector to the supervisor, SSL verification was successful.
However, the issue arose when the worker's phParser process and the collector process went down. After troubleshooting, the following error was found on the worker, supervisor, and collector:
- 2024-07-10T01:00:02.532543+03:00 fortiworker phDataManager[8988]: ACE_SSL (8988|9528) ecode: 336151568 - error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure
- 2024-07-10T01:00:02.532618+03:00 fortiworker phDataManager[8988]: ACE_SSL (8988|9528) ecode: 336462231 - 140E0197:SSL routines:SSL_shutdown:shutdown while in init.
I urgently need assistance to resolve this SSL certificate deployment issue.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @Merzeq_R,
Did you follow the guide https://docs.fortinet.com/document/fortisiem/7.1.7/configuring-ca-certificates/226157
If yes, and it is an urgent matter, please contact the TAC (via phone).
Something I like to note is that, in my experience, certificates might be overwritten after an update. Keep this in mind and have a look at that when upgrading.
Best,
Christian
Hello Secusaurus,
yes, I followed this guide but still issue exist.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.