Dear Friends,
I need your kind attention on a small problem and need your valuable suggestions.
I have enabled SSL inspection in my Fortigate policy which leads me to an certificate error in the Browser which i overcome by installing a Fortigate Certificate in the computer Browser like Mozilla / Chrome / IE/ etc , but what will i do with the Mobile devices like Android /Iphones where i have no option to manually install the Certificate.
Please do revert ASAP ... TqVM
Regards,
SANU
Yes you can manage CA trust-store on most mobile devices.
PCNSE
NSE
StrongSwan
In addition, how to install SSL cert onto Smart TV?
Do Apple and Android mobile devices respect commercially signed certificates as desktop and laptop browsers do?
yes the cert-storeholds any certifcate for rootCAs ( self signed, commercial, pre-canned factory, etc....)
Ken
PCNSE
NSE
StrongSwan
Depends but if the CA intermediates are installed in that mobile-device and trust than yes this would work. Keep in mind like 9k CA exist but only 200/1K are installed in any give OSes/devices CTLs. Keep in mind the SSL inspection is not a end-server certificate.
So if it's a well know CA than you should be good. I hope that helps.
PCNSE
NSE
StrongSwan
Keep this in mind if you go with a commercial certificate for the MiTM ssl-inspection, requires more effort on the end-users to acquire this certificate.
If your think about it, your acting like CAintermediate and dynamic resigning or "forging" ca-chain and issuer. So most CAs require more from you when they issue you a Certificate sign off the intermediate-chain. It's not like you can goto godaddy or comodo and ask give me my own-rootintermediate certificate cause I want to do SSL-decryption ;)
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.