Fortinet white logo
Fortinet white logo

Certificates

Certificates

The Certificates page allows you to manage both local and CA certificates. Certificates provide security assurance validated by a Certificate Authority (CA).

Notes:

  • If the administrative portal is inaccessible using Google Chrome, to generate a new self-signed certificate, see Help.

  • To upload certificates, bundle the Root CA, server certificate, and key file in tar.xz or .zip format.

  • You can upload certificates only in the .pem format. If the certificate is in another format, then convert it into the .pem format to upload.

  • To generate a certificate, it is mandatory to provide Subject Alternative Names (SAN).

  • When using CA2, combine the intermediate and root CA content into a single text file (.pem). This is required as only 3 files can be bundled and uploaded (mentioned in the preceding point).

Local Certificates

The Local Certificates section allows you to install certificate key pair by uploading a zip file containing a certificate and a private key file. The supported zip file formats include .tar, .tar.gz, tgz, zip, tar.xz, and .xz. Also you can generate a Certificate Signing Request (CSR).

Server certificates are generated based on a specific CSR. The CSR is a request sent from an applicant to a CA in order to apply for a digital identity certificate. When a CSR is generated, the associated private key to sign and/or encrypt connections is also generated. Click on the Generate CSR button and fill in the required information to generate a CSR for your certificate.

In the Certificate Signing Request window, enter the following.

  • Certificate Type - The type of the certificate, either CA signed or self signed.
  • Certificate Name - A name for the certificate.
  • Common Name - The FQDN or IP address of the server.
  • Organization - The name of your establishment or organization.
  • Locality - The city or area where your organization is located.
  • State or Province - The state or province of the above mentioned area.
  • Key Size - Either 2048 or 4096.
  • Subject Alternative Name (SAN) - Valid SAN values for FortiPresence VM include presence.<DOMAIN_NAME>, connect.<DOMAIN_NAME>, and presenceapi.<DOMAIN_NAME>, where <DOMAIN_NAME> is your preferred domain.
  • Optionally, you can enter the Organization Unit and the Country.
  • Click Generate.

CA Certificates

The CA Certificates section allows you to install and manage your CA certificate. To install a CA certificate, click Install CA Certificate and upload your CA certificate (.cer or .pem file). You can view details, download, or delete selected CA certificate after installation.

Certificates

Certificates

The Certificates page allows you to manage both local and CA certificates. Certificates provide security assurance validated by a Certificate Authority (CA).

Notes:

  • If the administrative portal is inaccessible using Google Chrome, to generate a new self-signed certificate, see Help.

  • To upload certificates, bundle the Root CA, server certificate, and key file in tar.xz or .zip format.

  • You can upload certificates only in the .pem format. If the certificate is in another format, then convert it into the .pem format to upload.

  • To generate a certificate, it is mandatory to provide Subject Alternative Names (SAN).

  • When using CA2, combine the intermediate and root CA content into a single text file (.pem). This is required as only 3 files can be bundled and uploaded (mentioned in the preceding point).

Local Certificates

The Local Certificates section allows you to install certificate key pair by uploading a zip file containing a certificate and a private key file. The supported zip file formats include .tar, .tar.gz, tgz, zip, tar.xz, and .xz. Also you can generate a Certificate Signing Request (CSR).

Server certificates are generated based on a specific CSR. The CSR is a request sent from an applicant to a CA in order to apply for a digital identity certificate. When a CSR is generated, the associated private key to sign and/or encrypt connections is also generated. Click on the Generate CSR button and fill in the required information to generate a CSR for your certificate.

In the Certificate Signing Request window, enter the following.

  • Certificate Type - The type of the certificate, either CA signed or self signed.
  • Certificate Name - A name for the certificate.
  • Common Name - The FQDN or IP address of the server.
  • Organization - The name of your establishment or organization.
  • Locality - The city or area where your organization is located.
  • State or Province - The state or province of the above mentioned area.
  • Key Size - Either 2048 or 4096.
  • Subject Alternative Name (SAN) - Valid SAN values for FortiPresence VM include presence.<DOMAIN_NAME>, connect.<DOMAIN_NAME>, and presenceapi.<DOMAIN_NAME>, where <DOMAIN_NAME> is your preferred domain.
  • Optionally, you can enter the Organization Unit and the Country.
  • Click Generate.

CA Certificates

The CA Certificates section allows you to install and manage your CA certificate. To install a CA certificate, click Install CA Certificate and upload your CA certificate (.cer or .pem file). You can view details, download, or delete selected CA certificate after installation.