Specify the use for the certificate.
For Certificate Use For, select Trusted Root
CA, and then click Save. The imported
certificate now appears in the list of certificates.
Confirm that the certificate is regarded as a Trusted Root CA
Certificate.
Under Custom Certificates, select the newly imported certificate. Then,
verify that the Usage column displays
Trusted Root CA Certificate.
Push Config to commit the configuration.
You have now repaired the broken certificate chain. The NGFW doesn’t block the
traffic because the CA issuer is now trusted.
Repeat this process for all missing intermediate certificates to repair their
certificate chains.