Skip to main content
cysaw
Staff & Editor
Staff & Editor
July 1, 2025

Technical Tip: Generate a Certificate using Let's Encrypt with Certbot for FortiMail

  • July 1, 2025
  • 0 replies
  • 887 views
Description This article describes how to generate a Certificate using Let's Encrypt with Certbot for FortiMail.
Scope FortiMail.
Solution
  1. Install Let’s Encrypt’s certbot and Apache module:


sudo apt-get update
sudo apt install certbot

 

  1. Execute the Following Command on Debian 9 or any Linux machine:


sudo certbot -d *.fnet.ml --manual --preferred-challenges dns certonly

  1. A code similar to the one below will be provided and should be used to add a new DNS TXT record to the public DNS server.


cysaw_0-1751331356622.png

 

  1. Configure a new TXT record on the Public DNS server. If a public DNS server is currently used, the verification via port 80 to the web server is not required to confirm ownership.


cysaw_1-1751331356625.png

 

  1. Wait for the public DNS server to be fully updated, then press Enter.
  2. The result below which indicating that the certificate has been successfully generated will be received:

 

Certificate and chain have been saved at:     /etc/letsencrypt/live/fnet.ml/fullchain.pem     
Key file has been saved at:     /etc/letsencrypt/live/fnet.ml/privkey.pem     
cert will expire on YYYY-MM-DD.
To obtain a new or tweaked version of this certificate in the future, simply run certbot again.
To non-interactively renew *all* of the certificates, run "certbot renew"

  1. Use SCP to access the Debian 9 /Linux machine and retrieve the certificate.
  2. Import the certificate into FortiMail.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!