Hi,
We introduced mandatory TLS (Security -> TLS -> TLS-Profile -> TLS-option = secure) a few months ago, which unfortunately has the disadvantage that connections are not only rejected when TLS is not an option on our connection partner but also get rejected if a TLS certificate on the receiving server has expired. Although encryption is still possible with an expired certificate, we then reject the SMTP connection. As far as I could find out, there is no possibility to configure a gradation in FortiMail. For example, if the server does not offer TLS, then reject the connection. But if it does offer TLS and only the certificate has expired, then connect.
Does anyone have any ideas on how we could implement this? It's quite annoying to keep an exception list for all customers who don't pay attention to their certificates...
Thank you!
| User | Count |
|---|---|
| 2913 | |
| 1451 | |
| 852 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.