| Description | This article describes how to configure Public Key Authentication from FortiNAC to FortiGate by generating an SSH public key on FortiNAC and enabling secure, passwordless administrative access on the FortiGate device. |
| Scope | FortiNAC, FortiNAC-F, FortiOS |
| Solution |
If the default key is not intended for use, a new public key can be generated using the command below:
execute ssh-authentication-keys generate nac ssh-ed25519
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAICQxxxxxxxxx/XZGpYAUdJVUlXZDVehWY+DN8 nac@ca1
When the key is implemented on the FortiGate, the 'nac@ca1' identifier at the end must not be included. config system admin set password <password>
Note: The password has to be specified for the created admin account. Otherwise, the created admin account could be used to login via HTTPS to the Admin GUI of FortiGate without a password.
Related article: FortiGate / FortiOS 7.6.5 Administration Guide - Public key SSH access |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.