Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
New Contributor III

WCF SSL Certificate Errors

Is anyone suddenly receiving certificate errors?  A large number of customers are reporting certificate errors when browsing exempted/trusted domains.  The SSL logs in the GUI show, "Server certificate blocked".

New Contributor III



I confirm, since 4:01 PM, i guess it's linked to the identrust expiration...

If you bypass the web filtering, no issue... but it's not a solution....


for information:

New Contributor

Talked to support.  They've confirmed they're working on it, but it is an issue with the Identrust expiration.  Probably going to turn off the expired cert filter.  I think that's about all we can do for now.


I just got off the phone with support.


Known issue.


Switch to Flow Based on your client policy (not Proxy) and that is a temp fix.


No ETA but support is on it.

New Contributor



You can check the box "allow invalid certificate" in the proxy SSL feature or configure the rule in flow based mode :(

But that's insane to do that on all ou fortigates we manage :\





Same here, with Lets Encrypt certificates.

New Contributor

I think it has something to do with


DST Root CA X3 that expired today, but I haven't found a work around for it.

New Contributor



Maybe blocked sites when using a Let's Encrypt certificate? (site not accessible with this  expired certificate problem)


I don'k know the good solution.

Defaut SSL/SSH inspection with the default "certificate-inspection" policy blocks the expired certificate.



New Contributor

I'm almost positive it's an issue with change of Let's Encrypt over to the ISRG certificate.  Every site that was reported blocked that I've reviewed is using a Let's Encrypt certificate.  I've got a case open and I'm waiting on a fix.  In the meantime, I've done the only thing I can by allowing expired certificates so people can continue to work.  Let's Encrypt is too commonly used to simply block any site using them.

New Contributor II

It appears FortiOS 6.4.x is immune to this situation as only our clients with firewalls running FortiOS 6.2 and earlier are affected.  Are any of you seeing the same pattern?


We are going with the allow invalid certs option until Fortinet addresses the issue.


Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Top Kudoed Authors