Is anyone suddenly receiving certificate errors? A large number of customers are reporting certificate errors when browsing exempted/trusted domains. The SSL logs in the GUI show, "Server certificate blocked".
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
I confirm, since 4:01 PM, i guess it's linked to the identrust expiration...
If you bypass the web filtering, no issue... but it's not a solution....
for information:
Talked to support. They've confirmed they're working on it, but it is an issue with the Identrust expiration. Probably going to turn off the expired cert filter. I think that's about all we can do for now.
I just got off the phone with support.
Known issue.
Switch to Flow Based on your client policy (not Proxy) and that is a temp fix.
No ETA but support is on it.
Hello,
You can check the box "allow invalid certificate" in the proxy SSL feature or configure the rule in flow based mode :(
But that's insane to do that on all ou fortigates we manage :\
Nicolas
Same here, with Lets Encrypt certificates.
I think it has something to do with
DST Root CA X3 that expired today, but I haven't found a work around for it.
Hello,
Maybe blocked sites when using a Let's Encrypt certificate?
https://docs.certifytheweb.com/docs/kb/kb-202109-letsencrypt/
https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/ (site not accessible with this expired certificate problem)
I don'k know the good solution.
Defaut SSL/SSH inspection with the default "certificate-inspection" policy blocks the expired certificate.
J.
I'm almost positive it's an issue with change of Let's Encrypt over to the ISRG certificate. Every site that was reported blocked that I've reviewed is using a Let's Encrypt certificate. I've got a case open and I'm waiting on a fix. In the meantime, I've done the only thing I can by allowing expired certificates so people can continue to work. Let's Encrypt is too commonly used to simply block any site using them.
It appears FortiOS 6.4.x is immune to this situation as only our clients with firewalls running FortiOS 6.2 and earlier are affected. Are any of you seeing the same pattern?
We are going with the allow invalid certs option until Fortinet addresses the issue.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1688 | |
1087 | |
752 | |
446 | |
227 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.