is it possible to use a verisign (or any other CA) for SSL inspection(web filtering, appcontrol) , in order to get rid of annoying certificate warning on https sites when using the inbuilt fortigate CA ssl proxy certificate.
If yes what type of certificate needs to be bought , a single ssl certificate etc....
from this discussion , i am doubtful about the possibility.
Apart from this i see no other way , by which the https certificate warning can be avoided completely. as smartphone, tabs , ipads are never part of domain so its not possible to use active directory infra to push local certificate and its a tedious task to install fortigate ssl proxy cert manually on every single device.
Solved! Go to Solution.
If a public CA started handing out signing certificates that people could use for SSL inspection the first thing I would do is remove their root from my browser store. Certificates are about trust... how can I trust a CA that lets others do SSL inspection on any site?
The short answer is no, this is what SSL is suppose to do, give you or let me re-phrase " the end-user the warning " & then he/she can make the validation to proceed after being warned.
PCNSE
NSE
StrongSwan
You can use a custom certificate for SSL inspection, instead of the default FortiGate cert. You can find instructions for how to do this here: http://cookbook.fortinet.com/preventing-certificate-warnings/#custom
Technical Writer, FortiOS
Let me know if there's anything you want to see added to the FortiGate Cookbook.
Hi,
Which version of the fortiOS are you using. After thinkering a little bit and a couple of forums found a solution for 5.2.1 and 5.2.2. I only the certificate issue on sites that are actually being barred from use.
Is that what you are looking for?
Carlitos loves firewalls
NSE4 (5.4,6.0)
NSE5 (Fortimanager 6.0, Fortianalyzer 6.0)
NSE7 (Enterprise Firewall 6.0)
hi all,
did not really understand well i have the same problem with ssl inspection i want to use a public ca with my ssl inspection for all my guest mobile phone, ipad, laptop etc
Help
If a public CA started handing out signing certificates that people could use for SSL inspection the first thing I would do is remove their root from my browser store. Certificates are about trust... how can I trust a CA that lets others do SSL inspection on any site?
Hi
Please follow the attach document. You can disable the replacement msg.
Regards
Bikash
Exactly, it's called a chain of trust for a reason 
PCNSE
NSE
StrongSwan
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.