FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
johnathan
Staff
Staff
Article Id 309209
Description

This article describes that the local Certificate is not selectable under SSL VPN settings, even though it is imported correctly

Scope

FortiGate v7.x.x+.

Solution

It is possible to run into a scenario where the Local Certificate is imported correctly, but it will not show up when trying to add it under SSL VPN Settings. This can happen especially if using custom PKI infrastructure (Active Directory, for example).

 

When creating a certificate in Active Directory using a Certificate Template, it is possible to choose whether it should be for 'Server Authentication' or 'Client Authentication'.

 

certservclient.PNG

 

For the certificate to be selectable within the SSLVPN, or for the Admin GUI interface, it would need to be set to 'Server Authentication'. This is visible in the FortiGate by double-clicking the certificate, and scrolling down to 'Extensions'.

 

Below is an example of a correct certificate:

 

correctCert.PNG


Below is an example of an incorrect certificate:

 

notcorrectCert.PNG