FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
JNDias
Staff
Staff
Article Id 241174
Description

This article describes the situations when FortiGate for EMS says: Server certificate and configured certificate are mismatched.

Scope FortiGate connected.
Solution

Verify an existing / renewed EMS Server Certificate

Some errors can occur:

 

JNDias_3-1672154512977.png

 

JNDias_4-1672154549064.png

 

1) From the browser connected to EMS, export the certificate (actually exporting the public certificate).

 

2) Import as a remote certificate on the FortiGate as a Remote Certificate.

 

3) Change the trusted certificate in the config by CLI.

 

Steps to follow:

 

1) From the browser connected to EMS, export the certificate (actually exporting the Public certificate).

 

JNDias_0-1672153820438.png

 

JNDias_1-1672153909107.png

JNDias_1-1672153909107.png

 

JNDias_2-1672153992530.png

 

Save as: 'Base64-encoded ASCII, single certificate (*.pem;*.crt)'.

 

2) Import the remote certificate on FortiGate as a Remote:

System -> Certificates -> Import -> Remote Certificate.

 
JNDias_1-1672156160462.png

 

3) CertificateChange the trusted cert in the config by CLI:

 

# config endpoint-control fctems

    edit <ems_name>

        set certificate <New Imported Remote Certificate>

    next

end

 

Related documents:

6.4.0 - Configuring other Security Fabric devices - FortiClient EMS

7.2.3 - Configuring other Security Fabric devices - FortiClient EMS