Skip to main content
mark8263
New Member
April 7, 2026
Question

ssl inspection certificate - which to use

  • April 7, 2026
  • 4 replies
  • 245 views

Hello all.

I am working thru the documentation about how to configure the sslvpn inspection for traffic.

I have a 'default' (trusted) cert on my 91G which shows as Fortigate_CA_SSl.

I also have purchased and installed a 'vpn.company.com' cert that my users utilize whenever connecting to my vpn - and that works well with mfa.

 

The documentation states that I need to import the cert to my users' devices (computer-trusted root certificates) location but doesn't mention which I should be using.  It also mentions that the certificate should be the same - in both places, meaning that the cert on the firewall and computer need to have/use the same cert in order for the process to work.

 

I presume that this would be, should I choose to use it - the 'default' cert mentioned above.  Is the correct or how do most people create/use a different cert for the ssl inspection.  

 

I plan to create, somehow, a small group of devices to utilize this process so that I can confirm whether the process (ssl inspection) is working or not before I push out to all users ... so if anyone has a suggestion for how to do that (sample users or device/ip addresses) please feel free to share.

 

thanks in advance.

mark

 

4 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
April 10, 2026

Hello mark8263, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
Toshi_Esumi
SuperUser
SuperUser
April 10, 2026

If you go to SSL/SSH Inspection Profile menu and open/view the deep-inspection profile, you would see only certificate that can be used here is Fortinet_CA_SSL. Because it has to be CA certificate. None of other certificates is usable by default for deep inspection.
SSLdeepinspection.png

 

 Those certificates you can purchase from like DigiCert, Sectigo, GoDaddy, etc. are server certificates, which you can use for SSL VPN or HTTPS admin access, etc., not CA certs.

You can of course generate a Private CA and issue Private CA certificates. But it requires a proper environment, like Win Domain Controller or MS Intune/MS Cloud PKI then issue certificate from there. Below explain how to do it via a domain controller.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Installing-private-CA-for-deep-inspection/ta-p/270767

Toshi

VinayHM
Staff
April 25, 2026

HI ​@mark8263 

FortiGate Certificate for SSL Inspection:The FortiGate uses a dedicated certificate to intercept and inspect SSL traffic. This is the inspection certificate that the FortiGate presents to clients during SSL inspection.

Root CA Certificate on Clients:Clients need to trust the FortiGate's inspection certificate (or more commonly, the CA that issued it). This involves importing the CA certificate (not the server certificate itself) into the trusted root store on client devices.

Choosing the Certificate:The certificate used by the FortiGate for SSL inspection is typically a self-signed CA certificate or an imported CA cert.  

If you're using a default FortiGate CA cert (e.g., Fortinet_CA_SSL), clients must trust this CA.  
If you generate your own custom CA (e.g., a corporate CA or your purchased cert's CA), then you import this CA into client trusted stores.

sw2090
SuperUser
SuperUser
April 27, 2026

plus you need to import this (sub)ca with private key on the Firewall and without key on the client(s)!

This is because the Firewall with DPI will intercept and decrypt the traffic and once inspection is done it needs  to re-encrypt the traffic to pass it to the client. Since it cannot have the private key of the original certificate it needs to have a CA to issue a cert + key that it can use the encrypt the traffic.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!