Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
drClays
New Contributor

Problem with https certificate - fqdn url view selfsign certificate

Hi,

 

I have got FortiGate 100F v6.4.7 build 1911 (GA) and I tried to implement cert from my ADCS to use a safe URL via FQDN.

 

I apply a certificate here:

drClays_0-1648539855521.png

 

but when I use URL https://fortigate.domain.local I have an untrusted certificate because I see a self-sign cert from Fortigate.

 

View from CLI:

drClays_1-1648540050048.png

 

View from the website:

drClays_2-1648540132104.png

 

View of implemented cert:

drClays_3-1648540230932.png

 

Where do I need to change to read my cert on a website?

10 REPLIES 10
pminarik
Staff
Staff

Does this certificate contain Subject Alternative Name (SAN) that matches the accessed FQDN? ("fortigate.xxx.local")

Setting just the CN to the desired FQDN is not sufficient in modern browsers, the SAN field must match the FQDN as well. Here's a screenshot of this website's SAN field to give a visual example:

community certificate SAN fieldcommunity certificate SAN field

This is not shown in your screenshot, so either it is missing, or the screenshot was just cut off. Alternatively, if you open developer tools panel in Chrome and open the security tab once the GUI is loaded, it should give a hint about what exactly is causing this certificate validation to fail.

[ corrections always welcome ]
Labels
Top Kudoed Authors