Certificates
The Certificates page allows you to manage both local and CA certificates. Certificates provide security assurance validated by a Certificate Authority (CA).
Notes:
-
If the administrative portal is inaccessible using Google Chrome, to generate a new self-signed certificate, see Help.
-
To upload certificates, bundle the Root CA, server certificate, and key file in tar.xz or .zip format.
-
You can upload certificates only in the .pem format. If the certificate is in another format, then convert it into the .pem format to upload.
-
To generate a certificate, it is mandatory to provide Subject Alternative Names (SAN).
-
When using CA2, combine the intermediate and root CA content into a single text file (.pem). This is required as only 3 files can be bundled and uploaded (mentioned in the preceding point).
Local Certificates
The Local Certificates section allows you to install certificate key pair by uploading a zip file containing a certificate and a private key file. The supported zip file formats include .tar, .tar.gz, tgz, zip, tar.xz, and .xz. Also you can generate a Certificate Signing Request (CSR).
Server certificates are generated based on a specific CSR. The CSR is a request sent from an applicant to a CA in order to apply for a digital identity certificate. When a CSR is generated, the associated private key to sign and/or encrypt connections is also generated. Click on the Generate CSR button and fill in the required information to generate a CSR for your certificate.
In the Certificate Signing Request window, enter the following.
- Certificate Type - The type of the certificate, either CA signed or self signed.
- Certificate Name - A name for the certificate.
- Common Name - The FQDN or IP address of the server.
- Organization - The name of your establishment or organization.
- Locality - The city or area where your organization is located.
- State or Province - The state or province of the above mentioned area.
- Key Size - Either 2048 or 4096.
- Subject Alternative Name (SAN) - Valid SAN values for FortiPresence VM include presence.<DOMAIN_NAME>, connect.<DOMAIN_NAME>, and presenceapi.<DOMAIN_NAME>, where <DOMAIN_NAME> is your preferred domain.
- Optionally, you can enter the Organization Unit and the Country.
- Click Generate.
CA Certificates
The CA Certificates section allows you to install and manage your CA certificate. To install a CA certificate, click Install CA Certificate and upload your CA certificate (.cer or .pem file). You can view details, download, or delete selected CA certificate after installation.