Hi,
i have a strange problem with pinterest.
When i enable the SSL Inspection in the explicit proxy, the site looks like in the pic in the attachment.
When i disable the inspection, everything is good.
The Certificate from Fortigate is installed on the Clients and every site is working but pinterest not.
Does anybody know why?
Its a Fortigate 110c with the 5.2.5 OS
Thx
Same issue with youtube.com
is it maybe youtube uses the google sha256 cert and on my Fortigate with OS 5.2.5 i have only the default sha1 cert "Fortinet_CA_SSLProxy" ?
I suspect it is caused by hsts as protocol. This means that FGT cannot act as man in the middle as far as I know, as long as you use a browser that supports hsts.
Check this kb article:
http://kb.fortinet.com/kb/documentLink.do?externalID=FD37095
HSTS is a security feature of the Google browser Chrome. It is designed to detect the man-in-the-middle SSL attacks by making sure that any certificate presented when accessing the Google resource is signed by a specific CA. If it detects any, CA it will simply refuse to continue the SSL handshake and prevent access to the website.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1110 | |
758 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.