Creating a CSR on the FortiGate
To create a CSR:
- On the FortiGate, go to System > Certificates and select Generate to create a new certificate signing request (CSR).
- Once created, the certificate will show a Status of Pending. Highlight the certificate and select Download.
Enter a Certificate Name, the Internet facing IP address of the FortiGate, and a valid email address, then configure the key options as shown in the example.
The Subject Alternative Name field must be configured with the internet facing IP address or FQDN in the following format: IP:x.x.x.x
or DNS:hostname.example.com
.
This will save a .csr file to your local drive.