Hi experts,
I am experiencing a certificate warning when users browse HTTPS websites such as Google.
The browser shows:
Your connection isn’t private
NET::ERR_CERT_COMMON_NAME_INVALID
Device Details:
Model: FortiGate 100E
Firmware: v6.2.16 build1392 (GA)
SSL Inspection Mode: Deep inspection (certificate inspection using Fortinet_CA_SSL)
Web Filter: Enabled
FortiGate certificate is already imported into client trusted root store
FortiGate DNS cache has been flushed (diagnose test application dnsproxy 8)
Tested browsers: Chrome, Edge (same issue)
Troubleshooting Done:
Verified system time on FortiGate and client
Flushed DNS cache on FortiGate and PC
Imported Fortinet_CA_SSL into Windows and Chrome store
Checked if FortiGate is presenting a mismatched CN (shows FortiGate CA instead of Google CN)
Question:
Is this a known issue with v6.2.16 build1392?
Any official Fortinet patch or workaround to fix SSL deep inspection mismatch?
Hi FNAC
In normal working, the DPI profile sets the certificate CN to the requested FQDN.
| User | Count |
|---|---|
| 2737 | |
| 1418 | |
| 812 | |
| 739 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.