Skip to main content
dirkdigs
New Member
June 6, 2019
Question

using multiple ssl certs on single server FortiWeb

  • June 6, 2019
  • 2 replies
  • 9119 views

this is with regards to a fortiweb VM

hello we have a server with multiple websites and multiple ssl certs in server policy it only allows a single cert to be attached.  is there a way to attach more than one ssl cert to a server policy?

    2 replies

    abelio
    SuperUser
    SuperUser
    June 6, 2019

     

    Another policy with same vserver, different serverpool/protected hostnames and different certificate

     

    You could also consider wildcard certificates in some scenarios with similar protection requirements.

    dirkdigs
    dirkdigsAuthor
    New Member
    June 7, 2019

    abelio wrote:

     

    Another policy with same vserver, different serverpool/protected hostnames and different certificate

     

    You could also consider wildcard certificates in some scenarios with similar protection requirements.

    I got this as Both sites use the "https" service

    "Two policies can not use the same Virtual Server and same Service"

     

     

     

    PS. What does protected hostnames used for? I have not been using this.......

    dirkdigs
    dirkdigsAuthor
    New Member
    June 10, 2019

    how does this work if i have two websites both on the same web server both using different ssl certificates?

    the server is listening on 443 for both sites

    how do i allow this connectivity through the fortiweb ?

    sohrab7sm
    New Member
    July 11, 2019

    I know you have to create policy per web site instead of per server. you should have multiple websites so you have policies and virtual servers as much as your websites. 

    therefore you can choose appropriate cert file depend on the website in policies.  

    Nikhil_Chaudhari
    New Member
    August 1, 2019

    Hello,

     

    Configure policy as HTTP Content Routing and add all content url with configuring SNI for the same it will work as expected.

     

    Thanks