FortiGate VPN – SSL Installation

Like the majority of server systems you will install your SSL certificate on the same server where your Certificate Signing Request (CSR) was created. Your private key will always be left on the server system where the CSR was originally created. Your SSL certificate will not work without this private key file. We will assume that this is the original system.

To install your SSL certificate on FortiGate VPN perform the following.

Step 1: Downloading your SSL Certificate & its Intermediate CA  Certificate:

  1. If you had the option of server type during enrollment and selected Other you will receive a x509/.cer/.crt/.pem version of your certificate within the email. Alternately you can access your Certificate User Portal by the supplied link in the email to pick up the x509 version of your certificate.
  2. Copy the SSL certificate and make sure to copy the —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—– header and footer Ensure there are no white spaces, extra line breaks or additional characters.
  3. Use a plain text editor such as Notepad, paste the content of the certificate and save it with extension .crt
  4. If your intermediate CA certificate for your product is not in the body of the email you can access your Intermediate CA also in a link within that email. Copy and paste the contents of your Intermediate CA into its own Notepad file and save it with a .crt extension also.
    Note: Some CAs may require two intermediates for best compatibility. These two are to be copied within their own corresponding .crt files and installed one at a time in a repeated process for intermediate installation.

Step 2: Importing your SSL Certificate:

  1. Log into your FortiGate System.
  2. Browse to System > Certificates.
  3. Select Import > Local Certificate.
  4. Browse to the location and path of your SSL certificate.
  5. Click OK.FortiGate Install
    The status of the certificate should change from PENDING to OK

Step 3: Importing your Intermediate CA:

  1. Browse to System > Certificates.
  2. Select Import > CA Certificate.
  3. Browse to the location and path of your Intermediate CA certificate.
  4. Click OK.
    Your Intermediate CA should be under the CA Certificate section of the certificates list.

Step 4: Configuring your FortiGate VPN to use the new SSL certificate:

  1. Browse to VPN > SSL > Settings.
  2. In the Connection Settings section under the Server Certificate drop down select your new SSL certificate.
  3. Click ApplyYou have configured the Foritgate VPN to use the new SSL certificate.

If you are unable to use these instructions for your server, Acmetek recommends that you contact either the vendor of your software or the organization that supports it.

FortiGate Support:

For more information refer to FortiGate.

Recent Posts

S/MIME for Outlook O365 Windows

Add to Favorites S/MIME Advantages of S/MIME Certificates S/MIME (Secure/Multipurpose Internet Mail Extensions) certificates offer several advantages when it comes to securing email communications. Here

Read More »

Abbreviations

Add to Favorites There are literally thousands of IT abbreviations out there. Many are concerned with the technical aspects of the computer, while others deal

Read More »

SSL Installation on Qmail

Add to Favorites SSL Installation on Qmail Qmail is a secure, reliable, efficient, simple message transfer agent. It is designed for typical Internet-connected UNIX hosts.

Read More »