Hello everyone,
We are currently experiencing an issue with SSL inspection causing an error in the certificate chain for our webmail hosted on the internet. The certificate we are using for the webmail is generated by GoDaddy, and we have successfully installed it on our Fortigate and server. However, when we perform an SSL check with SSL deep inspection enabled from an external source, it indicates that the certificate chain is broken. Interestingly, when we disable SSL deep inspection for that specific policy and conduct the test from outside, the certificate chain appears to be working properly.
As someone new to SSL configurations, I am seeking assistance in identifying the root cause of this issue. Our server team is attributing the problem to the Fortigate, as things seem to function correctly when SSL inspection is turned off. I would greatly appreciate any guidance on where to look and how to resolve this matter.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Can you please clarify whether mail server is behind the FortiGate or clients are behind FortiGate and mail server is hosted somewhere else.
The reason why I am asking is that there are 2 different scenarios when FortiGate is protecting server or clients.
Hi @mante,
Please note that when you enable deep inspection, FortiGate will replace the certificate with its own certificate. You can check which certificate is being used on the FortiGate GUI > Security Profiles > SSL/SSH Inspection > deep-inspection > CA certificate.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1666 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.