FortiADC
FortiADC enhances the scalability, performance, and security of your applications whether they are hosted on premises or in the cloud.
kmak
Staff
Staff
Article Id 299863
Description This article describes how to install the Let’s Encrypt SSL Certificate for a hostname using DNS-01 Challenge Type.
Scope FortiADC v7.0.0 and above. Domain DNS zone control to add/modify DNS records.
Solution
  1. In FortiADC, navigate to System -> Manage Certificates >- Local Certificate Tab and select Import.

 

kmak_0-1708136751967.jpeg

 

  1. In the Type dropdown menu of the Local Certificate Import page, select Automated.

 

kmak_1-1708136751971.jpeg

 

  1. After selecting Automated type, more settings will appear on the page. The Certificate Name will be used to identify the certificate. Insert the Domain Name on which the Let’s Encrypt SSL Certificate will be installed. Insert the Email Address which will be registered in the Let’s Encrypt SSL Email Notification mail. Keep the Key Type and Key Size unchanged, leave the Password empty, or insert only if necessary. Select Let’s Encrypt for ACME Service and the Challenge Type that suitable for the environment. In the example, the DNS-01 challenge type is used. Insert the Challenge Wait Time when the FortiADC will initiate the Let’s Encrypt Domain Validation before the Challenge Wait Time expires.

 

kmak_2-1708136751975.jpeg

 

  1. After selecting Save on the Local Certificate page, a page shall prompt with the DNS-01 Challenge TXT record to be added to the Domain Name.

 

kmak_3-1708136751978.jpeg

 

  1. Add the DNS TXT record before the Challenge Wait Time expires. Verify that the DNS TXT records query result.

 

kmak_4-1708136751985.jpeg

 

  1. The certificate status shows as Pending which the FortiADC has not initiated the domain validation or the domain has not completed the validation challenge.

 

kmak_5-1708136751990.jpeg

 

  1. The Local Certificate status shall show OK after the challenge wait time expires.

 

kmak_6-1708136751995.jpeg

 

  1. Select the Edit icon to check the SSL Certificate details.

 

kmak_7-1708136752002.jpeg

 

Related document:

Generating or importing a local certificate
Contributors