Hi all,
I am working on this for quite some time now. Maybe you can shed some light on this.
As soon as I touch one of the " s" -protocols in a protection profile (imaps, pop3s etc.) FortiOS installs a SSL proxy. Now when a client contacts an external mailserver (policy internal -> wan with this protection profile) the Fortigate sees the mailserver' s certificate and hands it down to the client BUT changes the " issuer" field to " Fortigate Inc." . This triggers a warning in the user' s mail client.
Technically it uses the built-in " Fortinet_CA_SSLProxy" cert.
OK, I do have an official certificate. I uploaded it and tried installing it using
" conf firewall ssl setting" , " set caname mycert"
but that was not possible as only the built-in cert is given as selectable.
When I look at the local, uploaded certs I see that only some bear the line " CA: true" . My own cert " mycert" shows " CA: false" .
Did I do something wrong while importing it?
How do you fix this issue with your Fortigate?
Ede Kernel panic: Aiee, killing interrupt handler!