| Description |
This article describes the steps for manually importing a public CA certificate bundle into FortiGate.
This can be needed in cases where for some reason some CA certificates or the whole bundle is removed from FortiGate or if the customer wants to manually downgrade or upgrade the CA certificate bundle. |
| Scope |
All FortiGate models and supported firmware. |
| Solution |
To verify whether the public CA bundle needs to be manually updated, follow these steps:
Navigate to the SSL/SSH Inspection profile, edit the profile used in the policy, and select 'View Trusted CA List'.
diagnose autoupdate versions | grep "Certificate Bundle" -A 6
Prerequisites:
execute vpn certificate ca import bundle <CA bundle filename with .pkg extension> <TFTP server IP>
Note: Ensure that the local firewall (if any) on the TFTP server allows access from FortiGate for retrieving the certificate package file before initiating the command. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.