Generate a new certificate
The FortiGate can generate a certificate using a pre-loaded, self-signed CA certificate: Fortinet_CA_SSL, instead of generating a CSR and providing it to a CA for signing. It is recommended that a server certificate from a well-known and trusted CA is used.
To generate a new certificate:
-
Go to System > Certificates and select Create/Import > Certificate.
-
Click Generate Certificate.
-
Set Certificate name to the name of the certificate. This is what is referenced when using the certificate in FortiGate configurations.
-
Set the Common name (CN) for the certificate. The common name should match the FQDN or IP of the primary SSL-VPN interface.
-
Optionally, set the Subject alternative name.
-
Click Download CA Certificate to download the CA certificate so that it can be installed or imported to all the machines that need to trust this certificate.
-
Click Create.
-
After the certificate is created, click Download Certificate to download the certificate. Click View Details to review the certificate details.
-
Click OK.