FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
Khidzir_MN
Staff
Staff
Article Id 378914
Description This article describes how to enable and require client certificates for specific URLs only.
Scope FortiWeb and FortiWeb-VM.
Solution

Prerequisite:

Enable the Client Certificate Verification in FortiWeb Server Policy by following the guide at the end of this article.

 

There is a requirement to require a client certificate from a client access for only a specific URL instead of the full website URL.

 

For example: 

 

FortiWeb provides the option to achieve this requirement using the URL Certificate feature. The feature supports multiple URLs.

 

Step 1: Create a new URL Certificate rule and specify the respective URLs:

 

url_cert.png

 

Step 2: Select and apply the URL Certificate rule created in Step1 for the respective Server Policy:

 

apply_server_policy.png

 

Note:

  1. The URL-based Certificate feature does not support HTTP2.
    HTTP2 needs to be disabled in the Server Policy.
                                                                
    httpdisabled.png                                                                                        
  2. Also, FortiWeb does not support URL-based Certificate Authentication with TLS1.3 even with PHA enabled on Client-Side. The TLS1.3 needs to be disabled in SSL Connection Settings.

                                                                     
tlsdisable.png

 

Related documents:
Technical Tip: How to enable Client Certificate Verification in FortiWeb Server Policy

How to apply PKI client authentication (personal certificates)