FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
simonz_FTNT
Staff
Staff
Article Id 195424

Description

 

This article describes how broken SSL/TLS certificate chains from missing intermediates can cause trust errors and offers solutions.


Scope

 
All models of FortiWeb.


Solution

 

Users may receive one of the following browser trust errors or prompts:

 

 

  1. 'Not Secure':

 

 

incorrect-intermediate-install-03.png

 

 

  1. 'Your connection is not private':

 

incorrect-intermediate-install-02-300x202.png

 

This is a known issue that occurs with certificates on mobile phone devices where the browser cannot locate the intermediate CA and will instead show an error message.

 
To resolve the issue, download the intermediate CA file from a certificate authority such as DigiCert.com or godaddy.com, then import it into FortiWeb by following the steps below:

  1. Go to Server Objects -> Certificates -> Intermediate CA.

  1. Select 'Import’ then 'Local PC' and choose the intermediate certificate file.

Intermediate_CA.PNG
 
  1. Select 'OK' to save it. Afterwards, the certificate should be displayed, as shown in the following screenshot:


Uploaded_Intermediate_Cert.PNG

 

  1. Select 'Intermediate CA Group' and then 'Create New' to create a new group or edit the existing group that would be used in the server policy.

  2. Provide the 'Intermediate CA Group' name and select 'OK' to save:

 

 
Next, select 'Create New' to add 'Inter_Cert_1' into the group.

Inter_CA_Group.PNG

  1. Finally, select the Intermediate CA group in the server policy under Policy -> Server Policy
    Edit the policy and choose the 'Certificate Intermediate Group' that was created earlier as shown below:
 
6.png