| Description |
This article explains the step-by-step process to create CA (certificate authority) certificates and certificates via FortiAuthenticator and use them on different applications (IPsec) where certificate authentication is required. |
||||||
| Scope | Creating certificates on FortiAuthenticator and applying them on FortiGate. | ||||||
| Solution |
Step 1: Creating Local CA certificate on FortiAuthenticator. Creating a local CA on FortiAuthenticator
The created local CA certificates will be displayed as below.
Step 2: Upload the CA certificate to FortiGate under the remote CA certificate.
Step 3: Generate CSR from FortiGate.
Under certificates, it will appear as pending.
Select it and download it as per the below screenshot.
Step 4: Go to the FortiAuthenticator, upload the downloaded certificate using the import button, and sign the request.
Step 5: After successfully signing the certificate, export it to be used in the FortiGate.
Step 6: Import the certificate to the FortiGate local certificate store as below.
Note 3: This can also be used in FortiGate's connected SSL VPN user and server with certificate authentication and other used cases as well. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.