Skip to main content
ByteHaven
Explorer III
May 3, 2026
Solved

FortiNAC self signed certificate

  • May 3, 2026
  • 5 replies
  • 86 views

Hello everyone,

 

I would like to know, will I have issues with the persistent agent if I use Fortinac’s Self signed certificate ? 

 

BR,

Best answer by AEK

Hi BH

Self-signed will not be trusted by the client, unless the client has the cert of the CA that signed the certificate.

So unless FortiNAC agent already imports the CA cert of NAC server on the host (which cannot be confirmed from my side), the connection between NAC client and NAC server will not be established, and you will see the NAC client always down (red bolt icon).

The solution is to always sign the CSR with a CA that is trusted by the clients, like your windows domain CA.

5 replies

AEK
SuperUser
AEKAnswer
SuperUser
May 3, 2026

Hi BH

Self-signed will not be trusted by the client, unless the client has the cert of the CA that signed the certificate.

So unless FortiNAC agent already imports the CA cert of NAC server on the host (which cannot be confirmed from my side), the connection between NAC client and NAC server will not be established, and you will see the NAC client always down (red bolt icon).

The solution is to always sign the CSR with a CA that is trusted by the clients, like your windows domain CA.

AEK
ebilcari
Staff
Staff
May 4, 2026

The Agent does not automatically trust or import the certificate from FNAC. While the Agent certificate can technically be exported from FNAC and manually imported on the end hosts, this is not recommended. More details can be found in this guide: Installing SSL Certificates.

Emirjon
ByteHaven
ByteHavenAuthor
Explorer III
May 4, 2026

I know it isn’t recommended, but when trying to export the created self signed certificate on FNAC, i get this error “cannot create export files without a valid certificate”.

 

I’ve seen this article, but it doesn’t work in my case, any tips please ?

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.