Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
StefanN
Visitor

TLS Profile on FortiMail and expired certificates

Hi,

We introduced mandatory TLS (Security -> TLS -> TLS-Profile -> TLS-option = secure) a few months ago, which unfortunately has the disadvantage that connections are not only rejected when TLS is not an option on our connection partner but also get rejected if a TLS certificate on the receiving server has expired. Although encryption is still possible with an expired certificate, we then reject the SMTP connection. As far as I could find out, there is no possibility to configure a gradation in FortiMail. For example, if the server does not offer TLS, then reject the connection. But if it does offer TLS and only the certificate has expired, then connect.
Does anyone have any ideas on how we could implement this? It's quite annoying to keep an exception list for all customers who don't pay attention to their certificates...

 

Thank you!

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors