Skip to main content
Khidzir_MN
Staff
Staff
August 25, 2025

Technical Tip: How to provide an Intermediate CA certificate for the Multi Certificate setup

  • August 25, 2025
  • 0 replies
  • 360 views
Description This article describes how to provide an Intermediate CA certificate for the Multi Certificate setup.
Scope FortiWeb and FortiWeb-VM.
Solution

FortiWeb supports using multiple server certificates (RSA, DSA, and ECDSA) for Server Policy using the Multi-certificate feature.
In some implementations, the server certificates may be signed by a different Intermediate CA certificate, respectively, and there is a requirement to provide the Intermediate CA certificate for each of the respective servers' certificates.

 

For this article's example, RSA and ECDSA certificates are used.

 

multi_certs.png

 

Step1: Upload the respective Intermediate CA certificate onto the FortiWeb:

 

intermediate_ca.png

 

Step2: Create Intermediate CA Group:

 

ca_group.png

 

Step3: Select the Intermediate CA Group created in Step 2 for the respective Server Policy:

 

server_policy_certs.png

 

Step4: Verify the correct Intermediate CA certificate negotiated with the client:

 

multicert_with_intermediate_ca_group.png

 

Note:

FortiWeb will provide all the Intermediate CA certificates in the Intermediate CA Group to the client.

 

Related document:

Uploading a server certificate