Troubleshooting Tip: Untrusted certificate warning in FortiGate for HTTPS sites using Entrust server certificates (2024)

Description

This article describes how to work around the untrusted certificate warning observed in the browser when visiting some HTTPS websites when FortiGate is configured in proxy mode and an SSL deep inspection profile has been enabled on a firewall policy.This is a known issue occurring with some of the HTTPS websites that use a server certificate issued by Entrust.Scope

Any supported version of FortiGate.


Solution

Symptoms.When FortiGate cannot successfully authenticate the server certificate (i.e. untrusted root CA, expired, self-signed certificate) it will present the CA certificate configured via set untrusted-caname in the SSL inspection profile (default CA certificate name: Fortinet_CA_Untrusted).

Troubleshooting Tip: Untrusted certificate warning in FortiGate for HTTPS sites using Entrust server certificates (1)

In some cases, HTTPS websites using server certificates issued by Entrust will encounter an untrusted root CA warning because the specified Entrust root CA certificate in the server certificate's chain of trust is not in FortiGate's Trusted CA list (see Security Profiles -> SSL/SSH Inspection -> View Trusted CAs List).

Explanation.

The issue is that the HTTP site's server certificate was issued by an intermediate CA associated with a specific Entrust root CA certificate that has been deemed invalid because of an invalid certificate property. Since this Entrust root CA certificate is invalid, it is not trusted by all browsers.

This issue can be confirmed by using the URL of the affected HTTPS site with an online SSL checker website like SSL Labs' SSL Server Test or SSL Shopper's SSL Checker, and observing the checker's result that the certificate chain is incomplete or the certificate is not trusted in all browsers.

The solution to this issue is for the website's administrator to remove the invalid Entrust root CA certificate from the web server and replace it with a valid Entrust root CA certificate, or to call Entrust for further assistance.

On FortiGate, the workaround is to download the invalid Entrust root CA certificate from the affected website via a web browser and then adding it to FortiGate's trusted CA list.

Important Note.
This workaround should be considered a short-term fix before the web site administrator implements the solution above on their end.

The workaround is implemented as follows:

  1. From a workstation behind the FortiGate with SSL deep inspection enabled, visit the affected web site.
  2. From a web browser, download the affected web site's invalid Entrust root CA certificate as follows:


Chrome/Internet Explorer.

  • From the browser, view the certificate within Windows' certificate window:
    Chrome: select the lock icon to the left of the HTTPS URL, and then select 'Certificate'.
    Internet Explorer: select the lock icon to the right of the Address bar, and then select 'View certificates'.
  • From the Certificate window, go to the Certification Path tab.
  • Select the top-most certificate and click on View Certificate.
  • In the second Certificate window, go to the Details tab and select 'Copy to File...'.
  • Follow the Certificate Export Wizard to export the certificate to the workstation in "DER encoded binary X.509 (.CER)" format.

Firefox.

  • Select the lock icon to the left of the HTTPS URL, and then select Connection secure -> More Information.
  • Select the View Certificate button to the right.
  • Select the Details tab in the Certificate Viewer.
  • Select the top-most certificate and select 'Export...'.
  1. On the FortiGate, perform these steps:
  • Go to System > Certificates and select Import -> CA Certificate.
  • Select File, select the invalid Entrust root CA certificate downloaded from the affected site, and select 'OK'.
  • Observe that the added invalid Entrust root CA certificate appears under the External CA Certificates section of the Certificates page.

Related document:
Explicit web proxy - FortiGate administration guide.

Troubleshooting Tip: Untrusted certificate warning in FortiGate for HTTPS sites using Entrust server certificates (2024)
Top Articles
What Makes A Pokémon The Strongest?
Deoxys (Pokémon Odyssey)
Lexi Vonn
Nco Leadership Center Of Excellence
Polyhaven Hdri
Poe Pohx Profile
Tanger Outlets Sevierville Directory Map
Lichtsignale | Spur H0 | Sortiment | Viessmann Modelltechnik GmbH
Autozone Locations Near Me
Which Is A Popular Southern Hemisphere Destination Microsoft Rewards
Ukraine-Russia war: Latest updates
The Binding of Isaac
Marion County Wv Tax Maps
The Shoppes At Zion Directory
Jesus Calling Oct 27
Are They Not Beautiful Wowhead
Cpt 90677 Reimbursem*nt 2023
Walgreens San Pedro And Hildebrand
Carson Municipal Code
48 Oz Equals How Many Quarts
Walgreens On Bingle And Long Point
Free T33N Leaks
27 Fantastic Things to do in Lynchburg, Virginia - Happy To Be Virginia
Big Boobs Indian Photos
Kempsville Recreation Center Pool Schedule
R/Orangetheory
O'reilly's Wrens Georgia
15 Downer Way, Crosswicks, NJ 08515 - MLS NJBL2072416 - Coldwell Banker
Rust Belt Revival Auctions
Bt33Nhn
Weekly Math Review Q4 3
Devotion Showtimes Near Mjr Universal Grand Cinema 16
Oxford Alabama Craigslist
Cherry Spa Madison
The Transformation Of Vanessa Ray From Childhood To Blue Bloods - Looper
NHL training camps open with Swayman's status with the Bruins among the many questions
888-333-4026
Bones And All Showtimes Near Johnstown Movieplex
Mid America Irish Dance Voy
Bcy Testing Solution Columbia Sc
Colorado Parks And Wildlife Reissue List
The Angel Next Door Spoils Me Rotten Gogoanime
Beaufort SC Mugshots
Bill Manser Net Worth
Dickdrainersx Jessica Marie
Poe Self Chill
Wolf Of Wallstreet 123 Movies
About us | DELTA Fiber
Tamilblasters.wu
The Love Life Of Kelsey Asbille: A Comprehensive Guide To Her Relationships
Obituaries in Westchester, NY | The Journal News
Códigos SWIFT/BIC para bancos de USA
Latest Posts
Article information

Author: Delena Feil

Last Updated:

Views: 5736

Rating: 4.4 / 5 (45 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Delena Feil

Birthday: 1998-08-29

Address: 747 Lubowitz Run, Sidmouth, HI 90646-5543

Phone: +99513241752844

Job: Design Supervisor

Hobby: Digital arts, Lacemaking, Air sports, Running, Scouting, Shooting, Puzzles

Introduction: My name is Delena Feil, I am a clean, splendid, calm, fancy, jolly, bright, faithful person who loves writing and wants to share my knowledge and understanding with you.