FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
simonz_FTNT
Staff
Staff
Article Id 195424

Description

 

This article explains how broken SSL/TLS certificate chains from missing intermediates can cause trust errors and offers solutions.


Scope

 
All models of FortiWeb.


Solution

 

Users may receive one of the following browser trust errors or prompts:

 

1) 'Not Secure':

 

incorrect-intermediate-install-03.png

 

2) 'Your connection is not private':

 

incorrect-intermediate-install-02-300x202.png

 

This is a known issue that occurs with certificates on mobile phone devices where the browser cannot locate the intermediate CA and will instead show an error message.

 
To resolve the issue, download the intermediate CA file from a certificate authority such as DigiCert.com or godaddy.com, then import it into FortiWeb by following the steps below:

1) Go to System -> Admin -> Certificates -> Admin Intermediate CA.

2) Select 'Import’ then 'Local' and choose the intermediate certificate.pem file.

1.png

 

2.png

 

 
3) Select 'OK' to save it. The following should display:

3.png

 

4) Select 'Intermediate CA Group' and then 'Create New' to create a new group or edit the existing group that would be used in the server policy.


5) Provide the 'Intermediate CA Group' name and select 'OK' to save:
 
4.png

 

Next, select 'Create New' to add 'Inter_Cert_1' into the group.

5.png

 

6) Finally, select the Intermediate CA group in the server policy under Policy -> Server Policy
Edit the policy and choose the 'Certificate Intermediate Group' that was created earlier as shown below:
 
6.png

 

 

Contributors