Skip to main content
nabilnowolf
New Member
January 20, 2022
Question

Fortinac Persistent Agent Certificate issue

  • January 20, 2022
  • 2 replies
  • 3119 views

Hi guys , please i would like to know if we can work with self signed certificate for communication between the agent and the fortinac server ?

 

We dont have an AD CA , and we cannot use third party certificate at the moment so we want to have this ssl communication done but with just some local self signed cert on the fortinac to be installed at the host for example .

 

Can you please advise on that , many thanks in advance .

2 replies

Hatibi
Staff & Editor
Staff & Editor
January 21, 2022

Hi Nowolf,

 

Self-Signed - FortiNAC issues its own certificate.

This type of certificate cannot be used for the Persistent Agent certificate target (for Persistent Agent communication) or the Portal target when using Dissolvable Agents.

 

You can check the docs below for more information on this and deployment scenarios:

 

https://docs.fortinet.com/document/fortinac/8.3.0/installing-ssl-certificates

https://docs.fortinet.com/document/fortinac/8.8.0/persistent-agent-deployment-and-configuration

 

Regards,

S

nabilnowolf
New Member
January 24, 2022

Hi ,

Fisrt of all thanks for replying .

So I used the csr to generate self signed certificate from fortinac with the correct cn name puted on the registre value of the persistent agent , and the SSL communication WORK as expected with an approval from the agent side .

I puted that answer so every one can use this workaround .

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!