Fortinet black logo
7.2.0

Troubleshooting

Troubleshooting

Related KB Articles

Private Key error when installing renewed SSL certificate

Invalid private key error while installing SSL certificate

Convert SSL private key to RSA format

Export SSL certificate and private key from keystore

Create SSL Certificate Bundle with Files Returned from Certificate Authority

Identify missing SSL certificates via administration UI

'One or more certificates are invalid' error

Error when updating Portal SSL mode or portal SSL certificate

If something is wrong with the uploaded certificate files, FortiNAC will display an error and will not apply the certificate.

Common Causes for Certificate Upload Errors

  • The wildcard name (e.g., *.yourcompany.com) was placed in the Fully- Qualified Host Name Field in the Portal SSL view under System > Settings > Security. To correct, change the entry to the true Fully-Qualified Host Name and click Save Settings.

  • There are extra spaces, characters, and/or carriage returns above, below, or within the text body of any of the files.

  • The certificate was not generated with the current key and there is mismatch.

    This can happen if the OK button in the Generate CSR screen had been clicked after saving the Certificate Request. Each time OK is clicked on the Generate CSR screen, a new CSR and private key are created, overwriting any previous private key.

    To confirm the certificate and key match, use the following tool: https://www.sslshopper.com/certificate-key-matcher.html

If the key and certificate do not match, generate a new CSR and submit for a new certificate.

Contact Support for further assistance.

Troubleshooting

Related KB Articles

Private Key error when installing renewed SSL certificate

Invalid private key error while installing SSL certificate

Convert SSL private key to RSA format

Export SSL certificate and private key from keystore

Create SSL Certificate Bundle with Files Returned from Certificate Authority

Identify missing SSL certificates via administration UI

'One or more certificates are invalid' error

Error when updating Portal SSL mode or portal SSL certificate

If something is wrong with the uploaded certificate files, FortiNAC will display an error and will not apply the certificate.

Common Causes for Certificate Upload Errors

  • The wildcard name (e.g., *.yourcompany.com) was placed in the Fully- Qualified Host Name Field in the Portal SSL view under System > Settings > Security. To correct, change the entry to the true Fully-Qualified Host Name and click Save Settings.

  • There are extra spaces, characters, and/or carriage returns above, below, or within the text body of any of the files.

  • The certificate was not generated with the current key and there is mismatch.

    This can happen if the OK button in the Generate CSR screen had been clicked after saving the Certificate Request. Each time OK is clicked on the Generate CSR screen, a new CSR and private key are created, overwriting any previous private key.

    To confirm the certificate and key match, use the following tool: https://www.sslshopper.com/certificate-key-matcher.html

If the key and certificate do not match, generate a new CSR and submit for a new certificate.

Contact Support for further assistance.