Hello,
I combined my web server domain certificate with intermediate certificate
[size="1"]-----BEGIN CERTIFICATE-----
[/size]
...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
...
-----END CERTIFICATE-----
to have full certification path. ssllabs.com gives website A rating.
Then I uploaded combined certificate to FortiGate 300E (v6.0.2 build0163 (GA)) System>Certificates>Import>Local CA> Certificate.
I created SSL inspection profile with that combined certificate (Protecting SSL Server, HTTPS 443) and applied this profile to my web server IPv4 Policy SSL inspection.
Now ssllabs.com gives rating B, because certificate chain is incomplete (intermediate certificate is missing). I downloaded certificate from FortiGate and confirmed that intermediate certificate was striped.
Any advice how to keep intermediate certificate when doing ssl inspection with FortiGate?
SOLUTION:
separately import the intermediate certificate, make sure that intermediate CA is under the External CA certificates.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1112 | |
759 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.