FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
gsharma
Staff
Staff
Article Id 395820
Description This article describes how to troubleshoot if FortiWeb is not able to connect to FortiGuard servers due to a certificate issue.
Scope FortiWeb.
Solution

FortiWeb is getting an issue on accessing the GUI, showing error 'License has been uploaded, Please wait a few seconds for license authentication with Fortinet registration servers. Require Internet connection'. This occurs if FortiWeb is unable to connect to FortiGuard servers.

 

fw-vm_webui.JPG

 

To get the debugs, the following commands can be used:


diagnose debug reset
diagnose debug application fds 7
diagnose deb application sslutil 7
diagnose debug enable
execute update-now

 

In the debugs, the following error can be seen:

 

(__ssl_info_callback : 432) SSLv3/TLS read server certificate request
(__ssl_verify_cb : 523) Something is wrong with certificate or certificate revoked, errorno(20).

 

This happens due to an expired certificate or an invalid certificate. If the Certificate is valid, then the upstream firewall has to be checked.

 

If the upstream firewall has deep SSL inspection enabled, it can cause the issue of certificate failure, as the firewall upstream can modify the certificate.

 

Workaround 

Disable SSL inspection and/or security profiles enabled in the firewall.

 

Note:

If disabling SSL inspection and/or security profiles enabled in the firewall does not make any difference, then reach out to the Support Portal for further troubleshooting.

 

Related document

Connecting to FortiGuard services