Skip to main content
aamin
Staff
Staff
December 3, 2021

Technical Tip: How to generate a self signed certificate from FortiGate

  • December 3, 2021
  • 0 replies
  • 43488 views

Description

This article describes how to generate a self signed certificate from Gui for internal use.

Scope

FortiGate.

Solution

FortiGate can generate a certificate using our self-signed: CA: Fortinet_CA_SSL. Using a server certificate from a trusted CA is strongly recommended.

Follow the steps to generate a self-signed certificate.

 

  1. Go to System -> Certificates and select 'Create / Import'.


Select 'Certificate'.

aamin_1-1638534693613.png

 

  1. Select the option to generate the certificate.


aamin_2-1638534825777.png

 

  1. Once it opens, fill in the details as per the requirements.

 

aamin_0-1638536557956.png

 

Ensure that the common name and subject alternative name are the ones that will be used to access the FortiGate or captive portal.

 

If the unit is to be accessed with an IP address, fill in the same here.


To use the domain in these fields, a DNS record has to be created on the local DNS server so that it resolves to this IP.

 

To redirect users to the captive portal FQDN instead of the IP address, use the following command.

config firewall auth-portal
    set portal-addr "fortinet-portal.company.abc"
end

 

Ensure that the CA certificate is downloaded in the situation screenshotted above to avoid certificate errors.

 

This can be pushed to clients using Windows AD GPO.

 

The certificate for the captive can be set in User & Authentication -> Authentication Settings.

 

f8f12596.png

 

To apply it on FortiGate admin login, go to System -> Settings -> Administration Settings -> HTTPS Server Certificate.

 

dcc69282.png

 

Note that when generating a self-signed certificate, there is no option available to select the key size, which may limit customization for certain security requirements. However, an efficient alternative is to generate a Certificate Signing Request (CSR) on FortiGate. This approach not only allows for the selection of the desired key size but also facilitates the submission of the CSR to FortiAuthenticator or any other third-party certificate authority. By utilizing this method, users can ensure that their certificates meet specific security standards and protocols that are crucial for their applications.

 

Related article:

Technical Tip: How to sign a CSR on FortiAuthenticator 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!