FortiSIEM Discussions
Merzeq_R
New Contributor

FortiSIEM SSL Certificate Issue

Hello,

ave a FortiSIEM setup with a supervisor, worker, and collector. I encountered an issue while deploying an SSL certificate to replace the default Fortinet certificate. I have three certificate files: server.pem, key.pem, and trustrootCa.crt. I initially deployed these certificates in /etc/httpd/conf.d/ssl.conf as follows:

  1. SSLCertificateFile /etc/httpd/conf.d/server.pem
  2. SSLCertificateChainFile /etc/httpd/conf.d/trustrootCa.crt
  3. SSLCertificateFile /etc/httpd/conf.d/key.pem
  4. The TrustRootCA was transferred to the worker and collector and imported into the ca-bundle.crt to be trusted. This was done by running the command update-ca-trust extract.

The SSL certificate was deployed on all servers using this configuration. When running curl -vv https://FQDN from the collector to the supervisor, SSL verification was successful.

However, the issue arose when the worker's phParser process and the collector process went down. After troubleshooting, the following error was found on the worker, supervisor, and collector:

 

- 2024-07-10T01:00:02.532543+03:00 fortiworker phDataManager[8988]: ACE_SSL (8988|9528) ecode: 336151568 - error:14094410:SSL routines:ssl3_read_bytes:sslv3 alert handshake failure
- 2024-07-10T01:00:02.532618+03:00 fortiworker phDataManager[8988]: ACE_SSL (8988|9528) ecode: 336462231 - 140E0197:SSL routines:SSL_shutdown:shutdown while in init.

I urgently need assistance to resolve this SSL certificate deployment issue.

MR
MR
2 REPLIES 2
Secusaurus
Contributor II

Hello @Merzeq_R,

 

Did you follow the guide https://docs.fortinet.com/document/fortisiem/7.1.7/configuring-ca-certificates/226157

 

If yes, and it is an urgent matter, please contact the TAC (via phone).

 

Something I like to note is that, in my experience, certificates might be overwritten after an update. Keep this in mind and have a look at that when upgrading.

 

Best,

Christian

FCP & FCSS Security Operations | Fortinet Advanced Partner
FCP & FCSS Security Operations | Fortinet Advanced Partner
Merzeq_R

Hello Secusaurus,

yes, I followed this guide but still issue exist.

MR
MR
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"