Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Richardschmd
New Contributor

FortiOS 5.2.3 Certificate Problems

Hi All

Since upgrading our Fortigate 100D to 5.2.3 we can no longer view the certificate page under "System-Certificates" the page is simply blank.... I've tried disabling and enabling the Certificate Feature but still nothing...

Could anyone point me in the right direction...

 

Please see attached image

 

15 REPLIES 15
emnoc
Esteemed Contributor III

I'm curious have you tried to import it by pasting via the cli ? If yes, does the config_file becomes corrupt?

 

This doesn't fix the webGUI import but at least let's you successfully insert a cert.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Robert2621

Yep - Have tried to import a EV cert via the CLI and same thing

even if this did work, it still would not solve the issue when upgrading from 5.2.2 to 5.2.3 it loosing the certificate menu as the certificate store contains EV certs

 

Note - normal certificates are not an issue - well for me at least

Robert2621
New Contributor

OH Great!

 

Wait till 5.2.4 for a fix says Fortigate support - this is simply unbeleivable!

 

 

gbadenes
New Contributor

I am facing exactly the same problem: as soon as I uploaded an EV certificate to the system, the "Certificates" page went blank. The worst part is the terrible technical support from Fortinet: I opened a case explaining exactly the problem and even telling them that the only new thing about the certificate (as compared to others that worked fine) was that it was EV.

They have been asking me to do all kinds of irrelevant tests and as of now they have not even identified the problem, recognised that it's a (known) bug or offered any workaround. The closest thing to a "solution" they have proposed is that I should contact the issuer of the certificate (!).

Luckily, a quick google search brought me to this thread. At least, now I see I'm not alone... However, that doesn't help much as there is still no solution in sight.

 

Don't the guys at Fortinet realise that EV certificates are business critical and should be supported? This is really disappointing!

 

seadave

gbadenes wrote:

I am facing exactly the same problem: as soon as I uploaded an EV certificate to the system, the "Certificates" page went blank. The worst part is the terrible technical support from Fortinet: I opened a case explaining exactly the problem and even telling them that the only new thing about the certificate (as compared to others that worked fine) was that it was EV.

They have been asking me to do all kinds of irrelevant tests and as of now they have not even identified the problem, recognised that it's a (known) bug or offered any workaround. The closest thing to a "solution" they have proposed is that I should contact the issuer of the certificate (!).

Luckily, a quick google search brought me to this thread. At least, now I see I'm not alone... However, that doesn't help much as there is still no solution in sight.

 

Don't the guys at Fortinet realise that EV certificates are business critical and should be supported? This is really disappointing!

 

I just had the same GD problem.  I created an EV EC cert and when I went to import it, blamo.  White screen on the certs page.  There is no corruption of the config.  The ONLY thing that has changed is the addition of that cert. I have not fully deleted it via the CLI yet.  I need to get my SSLVPN up and running with this.  Considering all of the bad feedback I've been reading regarding 5.2.4, I don't want to upgrade to that.  This is a brand new 500D that came with 5.2.1 on it I think.  I updated it to 5.2.3.  Everything else works fine.  This is a critical feature and needs to be resolved.  Were any of you able to get around it?  I'm starting to get really frustrated with the firmware surprises we are getting from Fortinet.  Sloppy coding and terrible QC is marring a great piece of hardware.  I just opened Ticket # 1483858, but I have 8x5 so I guess I'll hear back tomorrow.

 

One other note, I'm trying to use an EC and not an RSA cert.  EC is supposed to be better crypto based on what I've read.  It is offered as an option in the GUI and my CA supported it so that is what I used.  Maybe another case of don't use the best choice, use the one that works.  Ugh.

seadave
Contributor III

Fortinet got back to me.  Upgrade to 5.2.4 they said.  Based on this thread:

 

https://forum.fortinet.com/tm.aspx?m=126130&mpage=3#126697

 

I don't think that is a viable option.  So inane that they didn't catch something as critical as certs in QA.

Labels
Top Kudoed Authors