Skip to main content
ppatel
Staff & Editor
Staff & Editor
October 13, 2021

Technical Tip: How to import the CA certificate for full SSL inspection

  • October 13, 2021
  • 0 replies
  • 34476 views

Description

 

This article describes how to import the CA certificate that can be used to for full SSL inspection.


Solution

 
In order to import the CA certificate for full SSL inspection, import it with the private key and perform the certificate upload based on the file format: 
 
  • If there is a private key in the same file as the certificate, upload it via the following route: 
 
System -> Certificates -> Import -> Local Certificate -> PKCS#12

Note: If a new CA certificate is purchased, and exported from a third party unzip the folder and it has two files.  
File with Local certificate would be imported using the above path. However, other CRT files which is CA cert need to be imported by following the path 
 
 System -> Certificates -> Import -> CA Certificate -> File  
 
  • If there is a private key in a separate file from the certificate, upload it as: 
System -> Certificates -> Import -> Local Certificate -> Certificate.
 

Note:

  • Older FortiOS systems have the 'Certificates' section hidden from GUI, enable it first via the System -> Feature Visibility section.
  • In order to use the certificate, it must have the X509v3 Basic Constraints set to CA=True.

Related articles:

Technical Tip: Installing Private CA for Deep inspection

Technical Tip: How to enable deep inspection and import a certificate in the browser

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!