Skip to main content
martin_ivanov
New Member
February 1, 2019
Question

Can't upload self signed certificate: Incorrect certificate file key size for CA/LOCAL/REM

  • February 1, 2019
  • 3 replies
  • 6436 views

I am trying to generate self signed certificate/key, using openssl (1.1.0h) and following procedure:

openssl genrsa -aes256 -out fgtssl.key 2048

openssl req -new -key fgtssl.key -out fgtssl.csr

openssl x509 -req -days 365 -in fgtssl.csr -signkey fgtssl.key -out fgtssl.crt

 

When attempting to import into Fortigate (v6.0.3 build0200 KVM),  getting "Incorrect certificate file key size for CA/LOCAL/REM" .

 

I would like to configure IPSEC VPN dialup using own generated certificates.

What is wrong with the certificate ?

 

Martin.

    3 replies

    martin_ivanov
    New Member
    February 7, 2019

    IT turned to be licensing issue.

    It works just as expected.

    Lev
    New Member
    October 21, 2022

    I'm using Fortigate VM evaluation version, is this a reason why I can't upload new certificate to the firewall?

    m3ds0
    Explorer II
    April 5, 2024

    it seems the problem related with eva license cause is stuck with this error in my lab and i'm sure my certificate and private key format is correct!

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!