Description |
This article describes how to enable multiple certificates at the SSL profile in replace mode and explains the priority that the certificates take. |
Scope | FortiGate. |
Solution |
The FortiGate supports multiple certificates at a single SSL profile.
config firewall ssl-ssh-profile set server-cert-mode set server-cert name Certificate list.
Note: if the message shows 'Server certificate replace mode cannot support category exempt', follow these steps:
config firewall ssl-ssh-profile (ssl-ssh-profile) # edit "Multi-cert" edit "Multi-cert" config https set ports 443 set status deep-inspection set quic inspect end config ftps set ports 990 set status deep-inspection end config imaps set ports 993 set status deep-inspection end config pop3s set ports 995 set status deep-inspection end config smtps set ports 465 set status deep-inspection end config ssh set ports 22 set status disable end config dot set status disable set quic inspect end set server-cert-mode replace set server-cert "certificate_1" " certificate_2" " certificate_3" " certificate_4" " certificate_5" " certificate_6" " certificate_7" " certificate_8" " certificate_9" " certificate_10" next end
Related document: |