Description | This article describes how to sign and generate certificates using OpenSSL in Windows OS that can be used for SSLVPN and IPSec VPN configuration. |
Scope | FortiGate. |
Solution |
1). Create a CA with OpenSSL.
2). Generate a Certificate Request on the FortiGate and download it.
3). Sign the FortiGate certificate.
4). Import the signed certificate (VPNSSL.cer) into the FortiGate as 'local certificate'. This can now be used in IPSec or SSLVPN configuration as a server certificate.
Note: The certificates and private keys that were signed and generated should be located in the 'bin' folder of OpenSSL(i.e. C:\Program Files\OpenSSL-Win64\bin).
5). Create user certificate.
6). Upload cacertificate.pem to FortiGate as CA certificate. Bind this CA_Cert_X to the PKI users.
7). Import the usercert.pfx certificate into the Personal Section on the Certificates management console. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.