Hot!Full-Inspection issues with Internet Explorer and Firefox

Author
prowl65
New Member
  • Total Posts : 3
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/03/06 12:53:50
  • Status: offline
2020/03/06 13:05:05 (permalink)
0

Full-Inspection issues with Internet Explorer and Firefox

Have an interesting problem running FortiOS 6.2.3 on our Fortigate.  We utilize full SSL inspection with a Subordinate CA Cert signed by our domain CA.  IE, Firefox and Chrome work with the cert (Domain CA cert is in their trusts) for most sites as expected.
We do have one site we use that only Chrome is able to access. 
 
IE returns a Can't connect, security to this page, TLs, etc.....
FIREFOX returns returns a PR_END_OF_FILE_ERROR.
Chrome works.
 
Without the inspection all 3 browsers work to the site.
 
Using gnutls-cli the following is returned without inspection.
---------------------------------------------------------------------------------------------------------------------------
Resolving 'dttrackerv4.ca:443'...
Connecting to '67.223.104.81:443'...
- Certificate type: X.509
- Got a certificate list of 3 certificates.
- Certificate[0] info:
 - subject `CN=dttrackerv4.ca,OU=PositiveSSL,OU=Domain Control Validated', issuer `CN=Sectigo ECC Domain Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB', serial 0x34553ee56384fedbcc1c5da92cab5975, EC/ECDSA key 256 bits, signed using ECDSA-SHA256, activated `2019-10-15 00:00:00 UTC', expires `2020-10-14 23:59:59 UTC', pin-sha256="gFaKRMv4lh6ZWVJf2HebLzHJwd6C4D3IpsAtY8nZQF0="
        Public Key ID:
                sha1:14f3484943859d8174054c2f7361ee63daaa0e0d
                sha256:80568a44cbf8961e9959525fd8779b2f31c9c1de82e03dc8a6c02d63c9d9405d
        Public Key PIN:
                pin-sha256:gFaKRMv4lh6ZWVJf2HebLzHJwd6C4D3IpsAtY8nZQF0=

- Certificate[1] info:
 - subject `CN=Sectigo ECC Domain Validation Secure Server CA,O=Sectigo Limited,L=Salford,ST=Greater Manchester,C=GB', issuer `CN=USERTrust ECC Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US', serial 0x00f3644e6b6e0050237e0946bd7be1f51d, EC/ECDSA key 256 bits, signed using ECDSA-SHA384, activated `2018-11-02 00:00:00 UTC', expires `2030-12-31 23:59:59 UTC', pin-sha256="6YBE8kK4d5J1qu1wEjyoKqzEIvyRY5HyM/NB2wKdcZo="
- Certificate[2] info:
 - subject `CN=USERTrust ECC Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US', issuer `CN=AddTrust External CA Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE', serial 0x76d8b786d1f3524fee953e71403d99d5, EC/ECDSA key 384 bits, signed using RSA-SHA384, activated `2000-05-30 10:48:38 UTC', expires `2020-05-30 10:48:38 UTC', pin-sha256="ICGRfpgmOUXIWcQ/HXPLQTkFPEFPoDyjvH7ohhQpjzs="
- Status: The certificate is trusted.
|<1>| The hash size used in signature (20) is less than the expected (32)
- Description: (TLS1.2-X.509)-(ECDHE-SECP256R1)-(ECDSA-SHA1)-(AES-128-GCM)
- Session ID: AB:04:00:00:F0:CB:FF:0A:8E:F5:F9:F2:64:27:13:88:CF:C8:A4:85:DE:D8:F4:17:85:03:DB:1D:A8:CE:E0:B0
- Options: extended master secret, safe renegotiation,
- Handshake was completed
---------------------------------------------------------------------------------------------------------------------------
 
Using Full inspection the following is returned:
 
---------------------------------------------------------------------------------------------------------------------------
Resolving 'dttrackerv4.ca:443'...
Connecting to '67.223.104.81:443'...
*** Fatal error: The TLS connection was non-properly terminated.
---------------------------------------------------------------------------------------------------------------------------
 
Wondering if anyone has any ideas. I do have a tac case open but, they are looking for me to create new certs so that the end client has the private keys of the cert on the Fortigate. 
 
Thanks
 
#1

12 Replies Related Threads

    leviu
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/07/10 06:09:31
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/06/01 02:38:30 (permalink)
    0
    See this reddit post since the forum isn't that helpful. 
    See also this Sectigo/COMOD article.
    #2
    emnoc
    Expert Member
    • Total Posts : 5791
    • Scores: 381
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/06/01 05:17:09 (permalink)
    0
    The cert in his chain is expired , needs to be corrected and a new certificate issued,
     
    Ken Felix
     

    PCNSE 
    NSE 
    StrongSwan  
    #3
    Salas
    Bronze Member
    • Total Posts : 35
    • Scores: 0
    • Reward points: 0
    • Joined: 2005/02/21 01:21:06
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/06/01 06:12:00 (permalink)
    0
    I opened support ticket.
    The response is:
    "You are hitting a known issue ID: 638593 - Proxy Inspection Causing Certificate Errors

    The engineering team is currently working on this issue.

    The only currently known workaround is to use a "flow-based" inspection on the policy."
    #4
    Admin_FTNT
    Administrator
    • Total Posts : 94
    • Scores: 6
    • Reward points: 0
    • Joined: 2003/11/28 00:00:00
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/06/02 15:10:24 (permalink)
    0
    You may like to read this article: https://kb.fortinet.com/k...amp;externalId=FD49028
    #5
    lakshman
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/06/02 11:13:55
    • Status: offline
    nicolasross
    Bronze Member
    • Total Posts : 24
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/11/24 10:05:16
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/09/08 10:43:12 (permalink)
    0
    Salas
    "You are hitting a known issue ID: 638593 - Proxy Inspection Causing Certificate Errors

    The engineering team is currently working on this issue.

    The only currently known workaround is to use a "flow-based" inspection on the policy."

    That is strange. I was also having this issue, but it was a majority of websites, even docs.fortinet.com where the intermediate certificate is valid.
    That bug isn't shown in the known issue with 6.2.5...
    #7
    Alexander Mueller
    Bronze Member
    • Total Posts : 26
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/11/26 04:10:53
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 03:23:27 (permalink)
    0
    HI,
     
    is there any Solution, have upadate to 6.2.5 because ofproblem with the VPN, and now we have the same problem, but only with Firefox and Chrome, in IE the websites are working.
    If we open the website in IE, then its working in Chrome and Firefox, but only a period time, then problem is back
    #8
    nicolasross
    Bronze Member
    • Total Posts : 24
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/11/24 10:05:16
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 04:47:38 (permalink)
    0
    Alexander Mueller
    is there any Solution, have upadate to 6.2.5 because ofproblem with the VPN, and now we have the same problem, but only with Firefox and Chrome, in IE the websites are working.
    If we open the website in IE, then its working in Chrome and Firefox, but only a period time, then problem is back

    You can put the policy in flow mode. As per the ticket I opened, it's bug id 0617934. Will be fixed in 6.2.6, no ETA.
    #9
    Alexander Mueller
    Bronze Member
    • Total Posts : 26
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/11/26 04:10:53
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 05:21:20 (permalink)
    0
    Hi,
     
    we are using Proxy Policy and there no flow mode, its only in ipv4 Policy available and there its active
    #10
    nicolasross
    Bronze Member
    • Total Posts : 24
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/11/24 10:05:16
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 05:39:13 (permalink)
    0
    Alexander Mueller
    we are using Proxy Policy and there no flow mode, its only in ipv4 Policy available and there its active

    See there :

    #11
    Alexander Mueller
    Bronze Member
    • Total Posts : 26
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/11/26 04:10:53
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 05:42:35 (permalink)
    0

     
    In the Proxy Policy is no flow option
    post edited by Alexander Mueller - 2020/10/05 05:43:47

    Attached Image(s)

    #12
    nicolasross
    Bronze Member
    • Total Posts : 24
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/11/24 10:05:16
    • Status: offline
    Re: Full-Inspection issues with Internet Explorer and Firefox 2020/10/05 05:48:16 (permalink)
    0
    Alexander Mueller
    In the Proxy Policy is no flow option

    Hmmm. And you are with 6.2.5 ? I suggest you open a ticket with support.
    #13
    Jump to:
    © 2020 APG vNext Commercial Version 5.5