| Description | This article explains how to troubleshoot CSR generation if the certificate is generated without a Subject Alternative Name (SAN) using the FortiGate GUI. |
| Scope |
FortiOS 7.2.X, 7.4.X, 7.6.X. |
| Solution |
The Subject Alternative Name (SAN) attribute requires each value to specify its type, since a SAN entry can be any of several formats - DNS name, IP address, email address, URI, and others. Without a type, the SAN value becomes ambiguous and does not comply with the X.509 specification. The examples below show the difference between generating a CSR without and with proper SAN value types.
$ openssl req -text -in cst_without_sanType.csr
$openssl req -text -in csr_with_SAN_type.csr ... ... 49:67:f1:2f:20:6d:5c:a3:55:cb:b2:b5:0c:49:30:
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.