Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
serveradmin
New Contributor III

Intermediate certificate

Hi,

I have set up virtual server with full ssl offloading. Everything is working fine but when I check our website by ssl checker for example https://www.digicert.com/help/ it says that the server is not sending the required intermediate certificate. Anybody know how to fix it? The problem is that Bluemedia cannot correct ask our webserver because it gets error "Unable to find valid cerification path to requested target".

 

I have already tried to upload .pfx with certificate, intermediate certificate, private key etc. and it still does not work.

1 Solution
serveradmin
New Contributor III

Hi,

 

FYI, I downgraded fortios to 6.4.14 and it works! So it seems like it is bug in FortiOS 7.4.0. I will check if the same problem is also on fortios 7.2.5

View solution in original post

34 REPLIES 34
5Lights
New Contributor II

No nothing. For us, we couldn't re-produce the issue ourselves. Weirdly, it only affected SSL connections from a particular set of IPs.

We compared the CLIENTHELLOs in our successful requests, and their failed requests (where intermediate cert was not sent) and we saw nothing untoward.
Also, if we delete and re-add the web cert and/or intermediate  to the FG then it started working again temporarily (no change to the 3rd parties ClientHello)

After doing this a few times, it seems to have stuck and has now been working for 4 weeks.

Our suspicion was that maybe incoming requests are loadbalanced to different WAD processes, and maybe 1 off them had a bad cache of certs or something.
If this occurs again, we'll be logging the PID when doing a WAD debug.

EHoegee
New Contributor II

Thanks for the reply, Currendly with Fortigate on the line hopefully we find something.... Could I get the case number so I can forward this to the engineer?

eriksornes

Today I reversed the setings, as JasoSmit1 did, and it still works for me

EHoegee
New Contributor II

Did you got anything back from support? As I have the same issue but with a VIP loadbalancing setup an due to that I can't apply those settings or change the policy mode....

EHoegee
New Contributor II

Well they fixt it on 7.4.10 and also list it there as a bug fix.

However they did not list this as a bug on previous versions. I did ask the engineer to do this.

 

Did head a session with Fortinet and turns out that they released Fortios 7.4.10 in the release note's it is listed as a bug that is fixt on the release:
https://docs.fortinet.com/document/fortigate/7.4.10/fortios-release-notes/289806/resolved-issues

Bug ID    Description
1197212, WAD incorrectly prioritizes the default FortiGuard CA bundle over user-installed CAs when building certificate chains for cross-signed server certificates.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors