execute vpn certificate local export tftp FNETLAB p12 FNETLAB.p12 10.219.5.237Note: editing the PKCS#12 file or importing the PKCS#12 certificate back into another FortiGate unit afterwards requires knowing and using the password that was used at the time of the certificate export.
execute vpn certificate local import tftp FNETLAB.p12 FNETLAB.p12 p12 mypassword
execute vpn certificate local generate rsa FNETLAB 2048 fnet.lab.comOnce the process is finished, the ‘FNETLAB’ CSR is displayed in the GUI as follows:
Global certificate Signing State: Pending
config vpn certificate local3) Export the certificate CSR using the GUI:
edit FNETLAB
set password mypassword
end
execute vpn certificate local export tftp FNETLAB p12 FNETLAB.p12 10.219.5.2378) When using the exported FNETLAB.p12 file, a password will be asked. For example, in a Microsoft Windows environment, by double-clicking on the exported FNETLAB.p12 file, the Certificate Import Wizard will automatically be launched and there will be a request to enter the password for the private key (mypassword in that case)
C:\OpenSSL\bin>openssl pkcs12 -info -in ../mmwrk/FNETLAB.p12
Enter Import Password: <-- key-in mypassword
MAC Iteration 1
MAC verified OK
PKCS7 Encrypted data: pbeWithSHA1And3-KeyTripleDES-CBC, Iteration 2048
Certificate bag
Bag Attributes
friendlyName: FNETLAB
localKeyID: CC DA 03 36 C4 FE C3 7D 3F 2E D1 8A F3 B1 A2 F2 8B 02 29 BA
subject=/CN=fnet.lab.com
issuer=/C=FR/ST=AM/L=Valbonne/O=FNET/OU=L3/CN=FNET-LAB/emailAddress=mm@fnet.com
-----BEGIN CERTIFICATE-----
MIIFDjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQI4EmZ4UrIx0ECAggA
MBQGCCqGSIb3DQMHBAi/MlcxSQoYrgSCBMg8f9vvhII6DlTp1r6mLRYcvqBzA9WA
/DW7I9Z1gD9efS2WOSzhn9g5jrdWek8Bfa143n8FbChwLsQiow8qDB1mlmLzVWV1
Etc.
execute vpn certificate local import tftp FNETLAB.p12 192.xxx.xxx.xxx p12 mypassword
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.