Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: Invalid private key error while installing SSL certificate

  • September 28, 2018
  • 0 replies
  • 6003 views

Description


This article describes an issue when attempting to install a new SSL certificate with private key via the Administration UI and a message appears indicating that private key is invalid.

Scope

 

FortiNAC v8.x.

Solution

 
  1. Review the private key file using a text editor.  Alternatively, if in Linux, the file can be viewed by running the command:

 

cat <filename>


Key Header looks like this:
 
-----BEGIN PRIVATE KEY-----
MIIEvQIBADANBgkqhkiG9w0BAQEFAASCBKcwggSjAgEAAoIBAQC2jNIpG/iak9WT
QvhfPZHNp1jKbmlEf4KnV27i4nbIYp6kWYUegH/I64G3Q8AnP1IBP4KQruPmhxZs

Note: 
The header does not have "RSA" in it.  This is an indication the Key is not in the correct format and needs to be converted to RSA format. 
 
  1. Convert the private key file.  For instructions, refer to the related KB article below. Once properly converted, the header should look like this:


-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAtozSKRv4mpPVk0L4Xz2RzadYym5pRH+Cp1du4uJ2yGKepFmF

  1. Complete SSL Certificate upload using the newly converted private key file.

Related articles

Technical Note: Convert SSL private key to RSA format

Technical Note: Private Key error when installing renewed SSL certificate

Technical Tip: 'One or more certificates are invalid' error

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!