Technical Tip: How to generate a self signed certificate from FortiGate
Description | This article describes how to generate a self signed certificate from Gui for internal use. |
Scope | FortiGate. |
Solution | FortiGate can generate a certificate using our self-signed: CA:Â Fortinet_CA_SSL. Using a server certificate from a trusted CA is strongly recommended. Â
![]() Â
![]() Â
 ![]()  Ensure that the common name and subject alternative name are the ones that will be used to access the FortiGate or captive portal.  If the unit is to be accessed with an IP address, fill in the same here.
 To redirect users to the captive portal FQDN instead of the IP address, use the following command.  Ensure that the CA certificate is downloaded in the situation screenshotted above to avoid certificate errors.  This can be pushed to clients using Windows AD GPO.  The certificate for the captive can be set in User & Authentication -> Authentication Settings.  ![]()  To apply it on FortiGate admin login, go to System -> Settings -> Administration Settings -> HTTPS Server Certificate.  ![]()  Note that when generating a self-signed certificate, there is no option available to select the key size, which may limit customization for certain security requirements. However, an efficient alternative is to generate a Certificate Signing Request (CSR) on FortiGate. This approach not only allows for the selection of the desired key size but also facilitates the submission of the CSR to FortiAuthenticator or any other third-party certificate authority. By utilizing this method, users can ensure that their certificates meet specific security standards and protocols that are crucial for their applications.  Related article: |





