Created on
‎07-13-2023
02:54 AM
Edited on
‎02-26-2024
05:26 AM
By
Kate_M
Hi,
I have set up virtual server with full ssl offloading. Everything is working fine but when I check our website by ssl checker for example https://www.digicert.com/help/ it says that the server is not sending the required intermediate certificate. Anybody know how to fix it? The problem is that Bluemedia cannot correct ask our webserver because it gets error "Unable to find valid cerification path to requested target".
I have already tried to upload .pfx with certificate, intermediate certificate, private key etc. and it still does not work.
Solved! Go to Solution.
Hi,
FYI, I downgraded fortios to 6.4.14 and it works! So it seems like it is bug in FortiOS 7.4.0. I will check if the same problem is also on fortios 7.2.5
No nothing. For us, we couldn't re-produce the issue ourselves. Weirdly, it only affected SSL connections from a particular set of IPs.
We compared the CLIENTHELLOs in our successful requests, and their failed requests (where intermediate cert was not sent) and we saw nothing untoward.
Also, if we delete and re-add the web cert and/or intermediate to the FG then it started working again temporarily (no change to the 3rd parties ClientHello)
After doing this a few times, it seems to have stuck and has now been working for 4 weeks.
Our suspicion was that maybe incoming requests are loadbalanced to different WAD processes, and maybe 1 off them had a bad cache of certs or something.
If this occurs again, we'll be logging the PID when doing a WAD debug.
Thanks for the reply, Currendly with Fortigate on the line hopefully we find something.... Could I get the case number so I can forward this to the engineer?
Today I reversed the setings, as JasoSmit1 did, and it still works for me
Did you got anything back from support? As I have the same issue but with a VIP loadbalancing setup an due to that I can't apply those settings or change the policy mode....
Well they fixt it on 7.4.10 and also list it there as a bug fix.
However they did not list this as a bug on previous versions. I did ask the engineer to do this.
Did head a session with Fortinet and turns out that they released Fortios 7.4.10 in the release note's it is listed as a bug that is fixt on the release:
https://docs.fortinet.com/document/fortigate/7.4.10/fortios-release-notes/289806/resolved-issues
Bug ID Description
1197212, WAD incorrectly prioritizes the default FortiGuard CA bundle over user-installed CAs when building certificate chains for cross-signed server certificates.
| User | Count |
|---|---|
| 2928 | |
| 1456 | |
| 862 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.