This article describes how to sign a CSR on FortiAuthenticator. FortiAuthenticator can be used to sign a Certificate Sign Request (CSR) generated by other device like a
1.First, a Certificate Authority(CA) is required to sign certificates.
to Certificate Management > Certificate Authorities >
Local CAs then create a new root CA.
order to sign a CSR go to Certificate Management > End Entities > Users
and select Import.
the CA created.
b. A Subject Alternative Name can be specified. Note that FortiAuthenticator only supports E-Mail
and User Principal Name(UPN).
Note: If a CSR is imported with a Subject
Alternative Name as DNS or other fields, which is signed by the
FortiAuthenticator. Those fields (Subject Alternative Name) will be deleted.
Try to sign those CSR with other CA.
the propose of this certificate can be selected, add the key usages needed.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.