Technical Tip: How to deploy a certificate to multiple FortiGates in FortiManager using provisioning templates
| Description | This article describes how to assign a certificate to multiple FortiGates in FortiManager.
This article assumes that a CSR has been signed by a Certificate Authority and the private key is also embedded in the CSR. The certificate type may be a wildcard certificate. |
| Scope | FortiManager. |
| Solution | To deploy certificates using Provisioning Templates, the following process can be followed:
When the certificate is in PFX or PFX12 format, it will not appear as text because it is encrypted. Nonetheless, this can be converted to PEM format (clear text) using the procedure documented in Technical Tip: How to Convert a PKCS#12 Certificate to Legacy Format for FortiManager/FortiAnalyzer.
Configuration elements:
Method 1: Individual: Assign it to a device or group by moving the FortiGates from Available Entries to Selected Entries.
Method 2: Through template groups and template CLI groups. Assign the recently created CLI script to the CLI template group by creating or modifying a template.
Troubleshooting: The following commands can be used on the FortiManager CLI to debug the Installation:
diagnose debug application securityconsole 255 diagnose debug enable |





