Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
billp
Contributor

Help with Web Filter Override and Certificates

I' m having difficulty properly configuring certificates to work with Web Filter Block Override. Override works as expected, but users always get an SSL certificate error because their browser doesn' t recognize the Fortigate certificate on the override authentication page. Not too workable.. I' ve installed my own self-signed certificate and updated the CLI with the proper certificate name. Firefox gives the message, " sec_error_inadequate_key_usage" when trying to validate the override page with this cert, though. The cert works fine for deep SSL decrypting, but wondering if I need a separate cert for the Web Filter Block Overrride page? Any suggestions on making this work? Or do users simply need to click past this SSL error each time? Thanks. Bill

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
1 REPLY 1
billp
Contributor

Well, think I figured this one out on my own, if anyone' s interested. Sort of obvious. You can' t install a cert that will globally authenticate all sites. The cert name must match the URL, even if the cert is self-signed with a trusted root CA. I thought the FTG might be able to get around this with some tricks, but not possible AFAIK. So, there are two choices here. 1. Put up with the certificate errors. 2. Turn off SSL authentication for overrides by doing the following in the CLI: config webfilter fortiguard set ovrd-auth-https disable Your users will end up sending their credentials in cleartext to the FTG this way, though. (The manual mistakenly says that this feature is turned off by default, which is not true for any 4.x firmware release.) Sure would be nice if the FTG would redirect the authentication to a page that could take a self-signed cert. This really cuts into the usefulness of overrides. Bill

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1

Bill ========== Fortigate 600C 5.0.12, 111C 5.0.2 Logstash 1.4.1
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors