Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GenesisTechhub
New Contributor

When using proxy based UTM profiles I get Certificate Issues

I have been using the proxy based UTM profiles for all our students firewall profiles and have had no issues until last week. We started getting Certificate issues on client devices. such as Err_Cert_date_invalid. 

 

The certificate in question is issued by FortiGate but on inspection it is expired even though the certificate in the Manager is not expired. Im not even sure where to begin with this but it is causing issues as I have had to change to Fow based but this is allowing students to access sites that they shouldn't be despite rules being setup to prevent this.

 

Regards

7 REPLIES 7
abarushka
Staff
Staff

Hello,

 

Could you please clarify whether you are using default built-in certificate or imported CA certificate?

 

Moreover, I would like to ask whether you are using certificate inspection or deep inspection?

FortiGate
GenesisTechhub
New Contributor

Hi There

 

We are using the built in Fortinet_CA_SSL Certificate.

 

Regards

mriswan
Staff
Staff

Hello,
If you FGT is on v7.6, This issue might be related to the certificate manager feature change introduced in v7.6. The new option 'resigned-short-lived-certificate' feature is not working properly with certificate cache-timeout.
Please follow below KB for workaround:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-ERR-CERT-DATE-INVALID-err...

GenesisTechhub

Thank you mriswan. 

 

This has not resolved the issue. I found another customer with the exact same issue

full isnpection problem - Fortinet Community

 

No solution has yet been offered from Forti.

mriswan

Hi, Thank you for reply.

Can you check and change the below setting?

config firewall ssl setting
set cert-manager-cache-timeout 72 <---- adjustable between 24-720 hours, by default it is 72 (3 days)

GenesisTechhub

I tried the above and its not saving. When using show the setting after its not there.

 

abarushka

Hello,

 

You may consider to regenerate built-in CA certificate by running in CLI "execute vpn certificate local generate default-ssl-ca".

 

https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/663527/regenerate-default-ce...

 

FortiGate
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors