Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sanu
New Contributor

SSL Inspection error _ Mobile Devices

Dear Friends,

 

I need your kind attention on a small problem and need your valuable suggestions.

 

I have enabled SSL inspection in my Fortigate policy which leads me to an certificate error in the Browser which i overcome by installing a Fortigate Certificate in the computer Browser like Mozilla / Chrome / IE/ etc , but what will i do with the Mobile devices like Android /Iphones where i have no option to manually install the Certificate.

 

Please do revert ASAP ... TqVM

 

 

Regards,

SANU

san
san
11 REPLIES 11
packetpusher
Contributor

Great question! I've been thinking how to address that same issue by utilizing MDM. So far I haven't found a cost effective way to materialize my goal.
emnoc
Esteemed Contributor III

Yes you can manage CA trust-store on most  mobile devices.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
SecurityPlus

Do Apple and Android mobile devices respect commercially signed certificates as desktop and laptop browsers do?
packetpusher

In addition, how to install SSL cert onto Smart TV?

emnoc
Esteemed Contributor III

Do Apple and Android mobile devices respect commercially signed certificates as desktop and laptop browsers do?

 

yes the  cert-storeholds any certifcate  for rootCAs  ( self signed, commercial, pre-canned factory, etc....)

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
SecurityPlus

If the firewall has a commercial certificate (instead of default FortiGate or self signed certificate) does this eliminate the need to install the certificate in the mobile browser?
emnoc
Esteemed Contributor III

Depends but if the CA intermediates are installed in that mobile-device and trust than yes this would work. Keep in mind like  9k CA exist  but only 200/1K are installed in any  give OSes/devices  CTLs. Keep in mind the  SSL inspection  is not a end-server certificate.

 

So if it's a well know CA than  you should be  good. I hope that helps.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
SecurityPlus

Thanks
emnoc
Esteemed Contributor III

Keep this in mind if you  go with a commercial certificate for the MiTM ssl-inspection, requires more effort on the end-users to acquire this certificate.

 

If your think about it, your acting  like CAintermediate and dynamic resigning or "forging" ca-chain and issuer. So most CAs require more from you when they issue you a  Certificate sign off the intermediate-chain.  It's not like you  can goto  godaddy or comodo and ask give me my own-rootintermediate  certificate cause I want to do SSL-decryption ;)

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors