Fortinet white logo
Fortinet white logo

CLI Reference

system certificate local

system certificate local

Use this command to import signed certificates and certificate requests in order to install them for local use by the FortiMail unit.

FortiMail units require a local server certificate that it can present when clients request secure connections, including:

  • the web-based manager (HTTPS connections only)
  • webmail (HTTPS connections only)
  • secure email, such as SMTPS, IMAPS, and POP3S

When using this command to import a local certificate, you must enter the commands in the order described in the following syntax. This is because private-key will need the password to decrypt the private key if it was encrypted and certificate will try to find a matched private key file.

Syntax

config system certificate local

edit <certificate_name>

set password

set private-key

set certificate <certificate_str>

set csr <csr_str>

set comments <comment_str>

end

Variable

Description

Default

<certificate_name>

Enter a name for the certificate to be imported.

password

Enter a password for the certificate.

private-key

Enter a private key for the certificate.

Note: A random password is used to encrypt the private key, to prevent the private key from becoming visible when using the show command.

certificate <certificate_str>

Enter or paste the certificate in PEM format to import it.

csr <csr_str>

Enter or paste the certificate signing request in PEM format to import it.

comments <comment_str>

Enter any comments for this certificate.

Related topics

system certificate crl

system certificate remote

system certificate local

system certificate local

Use this command to import signed certificates and certificate requests in order to install them for local use by the FortiMail unit.

FortiMail units require a local server certificate that it can present when clients request secure connections, including:

  • the web-based manager (HTTPS connections only)
  • webmail (HTTPS connections only)
  • secure email, such as SMTPS, IMAPS, and POP3S

When using this command to import a local certificate, you must enter the commands in the order described in the following syntax. This is because private-key will need the password to decrypt the private key if it was encrypted and certificate will try to find a matched private key file.

Syntax

config system certificate local

edit <certificate_name>

set password

set private-key

set certificate <certificate_str>

set csr <csr_str>

set comments <comment_str>

end

Variable

Description

Default

<certificate_name>

Enter a name for the certificate to be imported.

password

Enter a password for the certificate.

private-key

Enter a private key for the certificate.

Note: A random password is used to encrypt the private key, to prevent the private key from becoming visible when using the show command.

certificate <certificate_str>

Enter or paste the certificate in PEM format to import it.

csr <csr_str>

Enter or paste the certificate signing request in PEM format to import it.

comments <comment_str>

Enter any comments for this certificate.

Related topics

system certificate crl

system certificate remote