Created on
12-27-2023
11:12 AM
Edited on
01-07-2025
12:32 AM
By
Jean-Philippe_P
Description | This article describes how to add an HTTPS certificate in FortiPAM for administrative access. |
Scope |
Any supported version of FortiPAM. |
Solution |
This article will use the following Fortinet products:
FortiPAM: Firmware version 1.1.2. FortiAuthenticator: Firmware version 6.5.2 (FortiAuthenticator will be used to sign CSR generated on FortiPAM. This can be replaced with any other PKI environment (For example: Microsoft Certificate Server or any other Internal or External).
After changing the admin-server-cert, the change also needs to be completed on the VIP:
config firewall vip edit "fortipam_vip" set uuid b1040.... set type access-proxy next end
Note: If there are multiple CAs in the environment, for example, Root CA -> Intermediate CAs, all of the CAs must be imported in FortiPAM and also on the client machine. From there, open GUI access to FortiPAM. In short: the CA chain must be completed on both FortiPAM as well as on the client machine, as it will otherwise lead to certificate errors in browsers.
Note: The 'RootCA' certificate must be trusted by the client machine. It has to be imported to the Trusted Root certificate authority store of the browser or Operating System.
Related documents: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.