| Description |
This article describes the procedure for generating a Certificate Signing Request (CSR) on FortiAuthenticator. FortiAuthenticator functions as a Certificate Authority, and a CSR is required when obtaining a trusted SSL/TLS certificate from a public Certificate Authority (CA), such as Let's Encrypt, DigiCert, GlobalSign, GoDaddy, etc. |
| Scope | FortiAuthenticator. |
| Solution |
There are three ways to generate a Certificate Signing Request (CSR) using FortiAuthenticator:
Below is an example with steps for generating a CSR for FortiAuthenticator System Access/Web Access: Navigate to Certificate Management → End Entities → Local Services → Create New. Populate the required fields with the following:
Subject Alternative Name and Key Signing Options must also be selected. It is important to notice that Common Name of certificate and Subject Alternative Name to be the same as FQDN of FortiAuthenticator
After creating the new certificate, its status will remain as Pending. To proceed, export the certificate, and a .csr file will be downloaded to the local PC.
The .csr file should be sent to the respective Public Certificate Authority (CA) for signing.
Once the signed certificate is received, navigate to End-Entities -> Local Services and import the certificate.
Typically, a .crt file is provided by the Public Certificate Authority (CA) for Local Services.
If a certificate with a private key is provided, select the following option: Type: Certificate and Private Key
After importing the certificate, the status can be checked, which should now display as 'Active'. Additionally, the Authority Key Identifier will indicate the Third-Party Issuer of the certificate:
This certificate can be associated by going to Administration -> System Access -> GUI Access -> HTTPS Certificate.
Note:
When configuring SSL/TLS certificates in FortiAuthenticator, it is important to understand the differences between using certificates signed by public Certificate Authorities (CAs) and those issued by a private CA. Each approach has specific benefits and considerations:
Using Public CA-Signed Certificates
Using Private CA-Signed Certificates
For queries about how FortiAuthenticator can sign other certificates, refer to Sign a CSR on FortiAuthenticator. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.