"Peer’s Certificate issuer is not recognized" when windows computer are procprotect with FortiGuard

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: www.ferramentafalco.com

I ran this command:

It produced this output:

My web server is (include version): apache 2.4

The operating system my web server runs on is (include version): Ubuntu 22.04
My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know):

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

Hallo
when I visit my website www.ferramentafalco from windows pc protect with Fortiguard antivirus , I receive this error SEC_ERROR_UNKNOWN_ISSUER , detailed error is this:

https://www.ferramentafalco.com/

Peer’s Certificate issuer is not recognized.

HTTP Strict Transport Security: false
HTTP Public Key Pinning: false

Certificate chain:

-----BEGIN CERTIFICATE-----
MIIKMDCCCRigAwIBAgIIVWv5C49braswDQYJKoZIhvcNAQELBQAwgakxCzAJBgNV
BAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRIwEAYDVQQHDAlTdW5ueXZhbGUx
ETAPBgNVBAoMCEZvcnRpbmV0MR4wHAYDVQQLDBVDZXJ0aWZpY2F0ZSBBdXRob3Jp
dHkxGTAXBgNVBAMMEEZHVDYwRlRLMjEwOUJNWE0xIzAhBgkqhkiG9w0BCQEWFHN1
cHBvcnRAZm9ydGluZXQuY29tMB4XDTI0MDMwNjExMjM0NloXDTI0MDYwNDExMjM0
NVowIjEgMB4GA1UEAxMXd3d3LmZlcnJhbWVudGFmYWxjby5jb20wggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQC/VW18xaEUUaeVNrkHklRlTO6rdRrZX6fz
SG2icSy8uCJF+5JTZ5JCAR/FNhuxEzLMN3KsXxMuTUJu02JNdAH/6jdH4/Z0JZZu
FECGdJNn13HA9hZ5H8x3dWGemKx9DfB3SuTb/BanZ6Co/TI8QZl6qjlxr+1rP92z
DN4op8H9aVAKJpnyJE14ZpOfgH8MTZsMdR9zO6b74wHw5LchPR0kMwCFHbhpKCeB
MoYZV44l+BHBZSR+ceaQAbN6nrGKr5bqxkZyk+YAax+wGKoBNgcQZRPqkvw93Mn5
EQTtasnBF0HLhosB/Ai2IHHP2ZU1DnTPg47nqvrTsWWZsJdn9UynAgMBAAGjggbg
MIIG3DAOBgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADA3BgNVHREEMDAughNm
ZXJyYW1lbnRhZmFsY28uY29tghd3d3cuZmVycmFtZW50YWZhbGNvLmNvbTCCBoEG
CWCGSAGG+EIBDQSCBnIKTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1N
TU1NTU1NTU1NTU1NTU1NCk1NTU1NTU1NTU1NTU1NTU1NTU1NTVdYMDBYV01NTU1N
TU1NTU1NTU1NTU1NTU1NTQpNTU1NTU1NTU1NTU1NTU1NTVdLa286LiAgLjtva0tX
TU1NTU1NTU1NTU1NTU1NTU0KTU1NTU1NTU1NTU5rZG9sYzsnLi4uLGxvb2MsLiAu
JztjbG9ka05NTU1NTU1NTU1NCk1NTU1NTU1NTU1PLiAuLDs6bGRPWFdNTU1NV0tr
ZGw6LCcuIC5PTU1NTU1NTU1NTQpNTU1NTU1NTU1NTy4gbFdNTU1NTU1NTU1NTU1N
TU1NTU1XYyAuT01NTU1NTU1NTU0KTU1NTU1NTU1NTU8uIGxNTU1XTlhOTlhYWFhO
TlhOV01NTWwgLk9NTU1NTU1NTU1NCk1NTU1NTU1NTU1PLiBsTU1XT2xsa09vbGxv
T2tsb09XTU1sIC5PTU1NTU1NTU1NTQpNTU1NTU1NTU1NTy4gbE1NTmtvb09YS0tL
S1hPb29rTk1NbCAuT01NTU1NTU1NTU0KTU1NTU1NTU1NTU8uIGxNTVh4bGxPTldN
TVdOT2xseFhNTWwgLk9NTU1NTU1NTU1NCk1NTU1NTU1NTU1PLiBsTU1XT29vTzB4
ZGR4ME9vb09OTU1sIC5PTU1NTU1NTU1NTQpNTU1NTU1NTU1NMCcgY1dNV1hreDBL
a3h4a0sweGtLV01XYyAnME1NTU1NTU1NTU0KTU1NTU1NTU1NTU5sIC54V01NTU1N
TU1NTU1NTU1NTU1XeC4gbE5NTU1NTU1NTU1NCk1NTU1NTU1NTU1NWGMgLmxYTU1N
TU1NTU1NTU1NTU1YbC4gY1hNTU1NTU1NTU1NTQpNTU1NTU1NTU1NTU1OeCcgLm9L
V01NTU1NTU1NV0tkJyAneE5NTU1NTU1NTU1NTU0KTU1NTU1NTU1NTU1NTU1YZCcg
Ljp4S1dNTVdLeDouICdkWE1NTU1NTU1NTU1NTU1NCk1NTU1NTU1NTU1NTU1NTU1O
a2MuIC4sOjosLiAuY2tOTU1NTU1NTU1NTU1NTU1NTQpNTU1NTU1NTU1NTU1NTU1N
TU1NWE9vOjs7Om9PWE1NTU1NTU1NTU1NTU1NTU1NTU0KTU1NTU1NTU1NTU1NTU1N
TU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NCk1NTU1NTU1NTU1NTU1N
TU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTU1NTQpNTU1NTU1NTU1NTU1N
TU1NTU1NTU1XWDAwWFdNTU1NTU1NTU1NTU1NTU1NTU1NTU0KTU1NTU1NTU1NTU1N
TU1NTU1XS2tvOi4gIC47b2tLV01NTU1NTU1NTU1NTU1NTU1NCk1NTU1NTU1NTU1O
a2RvbGM7Jy4uLixsb29jLC4gLic7Y2xvZGtOTU1NTU1NTU1NTQpNTU1NTU1NTU1N
Ty4gLiw7OmxkT1hXTU1NTVdLa2RsOiwnLiAuT01NTU1NTU1NTU0KTU1NTU1NTU1N
TU8uIGxXTU1NTU1NTU1NTU1NTU1NTU1NV2MgLk9NTU1NTU1NTU1NCk1NTU1NTU1N
TU1PLiBsTU1NV05YTk5YWFhYTk5YTldNTU1sIC5PTU1NTU1NTU1NTQpNTU1NTU1N
TU1NTy4gbE1NV09sbGtPb2xsb09rbG9PV01NbCAuT01NTU1NTU1NTU0KTU1NTU1N
TU1NTU8uIGxNTU5rb29PWEtLS0tYT29va05NTWwgLk9NTU1NTU1NTU1NCk1NTU1N
TU1NTU1PLiBsTU1YeGxsT05XTU1XTk9sbHhYTU1sIC5PTU1NTU1NTU1NTQpNTU1N
TU1NTU1NTy4gbE1NV09vb08weGRkeDBPb29PTk1NbCAuT01NTU1NTU1NTU0KTU1N
TU1NTU1NTTAnIGNXTVdYa3gwS2t4eGtLMHhrS1dNV2MgJzBNTU1NTU1NTU1NCk1N
TU1NTU1NTU1ObCAueFdNTU1NTU1NTU1NTU1NTU1NV3guIGxOTU1NTU1NTU1NTQpN
TU1NTU1NTU1NTVhjIC5sWE1NTU1NTU1NTU1NTU1NWGwuIGNYTU1NTU1NTU1NTU0K
TU1NTU1NTU1NTU1NTngnIC5vS1dNTU1NTU1NTVdLZCcwDQYJKoZIhvcNAQELBQAD
ggEBALAUdfmsFHHM78u5RtJK9F+khGhG03BvNLo1iO89hOCo4wuytzpAhz4cvQp2
koUGQSBSpf7va97CKPrQrnzrTyjRNU8/nrZQxh5EvpBBEUDtlvEF6LSbOXI0PYdB
60SOaqCn0PX5exxULe+kexPXbac1PyySZZIWg/cKM1WNuNcc7wzAF/TPeX5O+Szg
xAK0MdBD6MG7WUenuyFJb8ejnFDn3UWrPj8rdVhM60eJwcnxffBvOOxEb+Ixuw1M
VXWLm/XvfJGMTd6RtHqOniu9iauFG6o2Yi61hbkNck1oUQ+x05IVtMO6p/QKowoQ
PrKpIRWmz8qg8dr3WEn6aojZfYY=
-----END CERTIFICATE-----

Thanks in advance for your support

1 Like

Your webserver and certificate are fine.

FortiGuard is using some blacklist that includes either your domain name or your ip address.

It should tell you what the problem is if you click past the TLS error.

4 Likes

The cert shown is from your FortiGate 60F:

The problem you are seeing is caused by your own systems/design/configuration.

4 Likes

Thanks for your feed back
I don't know what's could be my problem, I try to update openssl, pyton, I verify my virtualhost but the issue is the same....
Could you suggest a possible problem?
thanks in advance

Talk to whomever controls the FortiGate firewall.
Mention "HTTPS inspection" and show them the certificate it presents you with.

5 Likes

Ok Thanks, I will try to do it

3 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.