Skip to main content
Hussien_Idris
Explorer
September 12, 2015
Solved

Client certificate for SSLVPN

  • September 12, 2015
  • 6 replies
  • 23913 views

Hi, i have created an openssl certificate and successfully imported to fortigate then downloaded the selfsigned certificate and imported to my machine. I want to introduce the two factor security i.e. load a certificate onto each of the clients that are connecting to the Fortigate. I have selected the option ' Require Client Certificate' but am not sure what Certificate to use? appreciate your cooperate and feedback regarding how to add certificate to be selected from the client certificate in forticlient tool. attached FYR..

 

thank you

 

Hussien Idris

    Best answer by emnoc

    Good now here's a few things to check out

     

    [ul]
  • is the certificate  sha1 or sha256? ( I've had no luck with SHA256 certs BTW  YMMV)[/ul][ul]
  • What cert-store did you installed it in ? ( personal > Certificates )[/ul][ul]
  • Is the certificate labeled for "user-authentication"  purpose ?[/ul][ul]
  • Did you apply or not-apply  a passphrase  during the import?[/ul][ul]
  • Is the certificate valid ( not expired )?[/ul][ul]
  • Is your system clock good  & correct ?[/ul]

     

     

    Use windows prompt certmgr.msc and validate the above and storage. And restart the forticlient.

     

     

  • 6 replies

    Paul_S
    New Member
    September 21, 2015

    Did you get this figured out? Do you understand PKI and how a CA behaves?

    theG
    New Member
    October 10, 2015

    Hi,

     

    I'm also having this same issue. I've managed to get Forticlient working on Android + IOS devices with the same certificate also generated from OpenSSL, but not windows based device because it's not showing the certificate...

     

    Anyone out there have a working solution on how to get the certificate to show up in Forticlient for windows?

     

    G

    emnoc
    New Member
    October 11, 2015

    1st question, what type or format is the certificate in pem or pkcs12? You will need to have probably convert the certificate into pkcs12 ( aka p12 ) and you can do that via a openline  convertor or via openssl

     

    openssl pkcs12 -export -inkey < the key file > -in < the certificate file > -out < the new pkcs filename>

     

    Than import the  new pkcs file via the windows certificate manager.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!