Good day,
I am getting a lot of Microsoft URLs being re-signed as untrusted see below, I have a FGT200F running firmware 7.
I have noticed that the Destination is not the same as the hostname, any thoughts as to what is happing?
Server certificate is re-signed as untrusted, certificate-status: untrusted.
Destination hostname
v10.events.data.microsoft.com uk-v20.events.data.microsoft.com
teams.events.data.microsoft.com uk-v20.events.data.microsoft.com
v10.vortex-win.data.microsoft.com uk-v20.events.data.microsoft.com
sevillecloudgateway-uks-prd.trafficmanager.net winatp-gw-uks.microsoft.com
uk-mobile.events.data.microsoft.com uk-v20.events.data.microsoft.com
eu-v10c.events.data.microsoft.com eu-v10c.events.data.microsoft.com
wd-prod-cp.trafficmanager.net unitedkingdom.cp.wd.microsoft.com
atm-settingsfe-prod-geo2.trafficmanager.net settings-win.data.microsoft.com
onedscolprduks03.uksouth.cloudapp.azure.com uk-v20.events.data.microsoft.com
settings-prod-cin-1.centralindia.cloudapp.azure.com settings-win.data.microsoft.com
geo.prod.do.dsp.mp.microsoft.com geo.prod.do.dsp.mp.microsoft.com
52.140.118.28 settings-win.data.microsoft.com
ic3.events.data.microsoft.com uk-v20.events.data.microsoft.com
browser.events.data.microsoft.com uk-v20.events.data.microsoft.com
eu-mobile.events.data.microsoft.com eu-v10c.events.data.microsoft.com
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 06-26-2024 06:49 AM Edited on 06-26-2024 06:51 AM
Hi @julianhaines ,
In the article that I have mentioned there is the procedure:
Chrome/Internet Explorer.
Firefox.
The article below also might help ("Viewing a certificate" paragraph):
https://support.mozilla.org/en-US/kb/secure-website-certificate
Best regards,
Hi @julianhaines ,
It seems that there are a few issues with those websites' certificates (chain broken or name mismatch), it does not look a FortiGate problem.
I have checked a couple of websites and for some of them the SSL chain of trust is broken. In that case you could import the Root CA into the FortiGate to resolve it.
For example:
https://www.sslshopper.com/ssl-checker.html#hostname=v10.events.data.microsoft.com%20
https://www.sslshopper.com/ssl-checker.html#hostname=eu-v10c.events.data.microsoft.com
https://www.ssllabs.com/ssltest/analyze.html?d=v10.events.data.microsoft.com
For the following there is a name mismatch (server side issue).
The below might help:
Best regards,
Thanks for the information, how would I know what CA's I would need and where to download?
Thanks
Created on 06-26-2024 06:49 AM Edited on 06-26-2024 06:51 AM
Hi @julianhaines ,
In the article that I have mentioned there is the procedure:
Chrome/Internet Explorer.
Firefox.
The article below also might help ("Viewing a certificate" paragraph):
https://support.mozilla.org/en-US/kb/secure-website-certificate
Best regards,
Hi I recommend you should use CloudFlare for security purposes. The reason behind they provide free certificate and trusted service.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1548 | |
1032 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.