Does this certificate contain Subject Alternative Name (SAN) that matches the accessed FQDN? ("fortigate.xxx.local")
Setting just the CN to the desired FQDN is not sufficient in modern browsers, the SAN field must match the FQDN as well. Here's a screenshot of this website's SAN field to give a visual example:
community certificate SAN field
This is not shown in your screenshot, so either it is missing, or the screenshot was just cut off. Alternatively, if you open developer tools panel in Chrome and open the security tab once the GUI is loaded, it should give a hint about what exactly is causing this certificate validation to fail.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.