Creating a certificate
To create a certificate:
- Go to System > Certificates.
- From +Create/Import, select Certificate.
The Create Certificate window opens.
- From the Automatically Provision Certificate pane, select Use Let's Encrypt to automatically create a certificate using the ACME protocol with the Let's Encrypt service.
The Certificate Details tab opens.
- In Certificate name, enter the name for the certificate.
- In Domain, enter the public FQDN of FortiPAM.
- In Email, enter the email address.
- Click Create.
If this is your first time enrolling a server certificate with Let's Encrypt on the FortiPAM unit, the Set ACME Interface pane opens.
- Select + and from Select Entries, select a port, or create new interfaces on which the ACME client will listen for challenges to provision and renew certificates.
It is suggested that you select one of the existing entries and use the port interface for FortiPAM access which is
port1
in most cases. - Click Close.
- Click OK.
Wait for Let's Encrypt to provision the certificate.
After successfully creating the certificate, the newly created certificate can be viewed or downloaded.
- Enable ACME Log to see logs related to the certificate created using the ACME protocol.
If the certificate cannot be created, the ACME log is displayed for troubleshooting.
Delete the certificate that could not be provisioned from the certificates list.
Use the following CLI command to check the ACME status:
diagnose system acme status-full <domain> #displays the latest ACME trace log for <domain>