Skip to main content
bkarl
Staff
Staff
March 18, 2024

Technical Tip: How to distribute a Fortinet CA SSL certificate on a local domain on a Windows Server

  • March 18, 2024
  • 2 replies
  • 12264 views
Description

The article explains how to distribute a Fortinet Root or Intermediate Certificate (CA) to ensure that devices on the network trust the certificate used by the FortiGate, especially in the case of SSL Inspection or SSL VPN. This is done using Group Policies (GPO) in an Active Directory environment.

Scope FortiOS Windows Server.
Solution

Go to Group Policy Management on the Windows Server.

 

KB 31 1.jpg

 

Create a new GPO if it does not exist:

 

KB 31 2.jpg

 

In this case, the GPO's name is 'test'. Right-click and select 'Edit'.

 

KB 31 3.jpg

 

After, navigate to Computer Configuration -> Windows Settings -> Security Settings -> Public Key Policies -> Trusted Root Certification Authorities -> 'Right-Click' and choose the Import option -> Next, choose the path where the certificate file is, then finish the installation.

 

KB 31 4.jpg

 

The client PCs can either be restarted or have the GPO manually synced by running the following command:

gpupdate /force

 

 

Fortinet devices do not apply GPOs directly; this is an Active Directory functionality. It is mandatory that an Active Directory domain controller with GPMC, or a device running RSAT, can reach a domain controller.

2 replies

lpedraza
Staff
Staff
August 23, 2024

@bkarl Thank you so much for your contribution!!! please keep up the great work!

lpedraza
Staff
Staff
August 23, 2024

@Stephen_G We do appreciate your contribution!!!

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!