Description | This article describes the error observed on FortiSwitch and outlines the possible cause and solution. |
Scope | FortiSwitch OS versions: v7.4.2, v7.6.2. |
Solution |
Issue: In FortiSwitch logs, continuous error messages may be observed regarding SSL certificate alerts:
Log message from FortiSwitch event:
Cause: The error occurs because the FortiSwitch does not recognize the client certificate presented by the device attempting to connect over HTTPS. In this case, the client is the device trying to access the FortiSwitch via HTTPS.
Resolution: Upgrade the FortiSwitch to v7.6.4 or later, where a new option (https-ssl-log-level) is available. Setting this option to critical will suppress these repetitive log messages.
Configuration example:
config system web
This change ensures only critical SSL errors are logged, avoiding repetitive certificate alerts.
Note: FortiSwitch may sometimes produce very similar error messages with 'ssl/tls alert certificate unknown' instead of 'sslv3 alert certificate unknown.'. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.