FortiWeb
A FortiWeb can be configured to join a Security Fabric through the root or downstream FortiGate.
kmak
Staff
Staff
Article Id 288512
Description This article describes how to obtain a Let’s Encrypt Certificate for a domain in FortiWeb with HTTP validation (True Transparent Proxy Mode).
Scope FortiWeb.
Solution

Prerequisite:

  • Domain/FQDN must pointed to the FortiWeb.
  • Domain/FQDN HTTPS/HTTP must be publicly accessible.

 

  1. In FortiWeb, navigate to Server Objects -> Certificates -> Let’s Encrypt. Create a new Let’s Encrypt Certificate request.

 

 

kmak_0-1702088948232.jpeg

 

  1. Select the request type to use HTTP-01, whereby Let’s Encrypt will be validating the domain SSL request using the HTTP validation method. Insert the name and the domain name.

 

kmak_1-1702088948237.jpeg

 

  1. The Let’s Encrypt cert will be in the init state. Do not click the issue icon before adding the Let’s Encrypt cert in the Server Pool.

 

kmak_2-1702088948240.jpeg

 

  1. Navigate to the Server Pool where the Let’s Encrypt Domain/FQDN pointing to.

 

kmak_3-1702088948242.jpeg

 

 

  1. Select Let’s Encrypt as the Certificate Type. Then select the created Let’s Encrypt Cert.

 

kmak_4-1702088948246.jpeg

 

  1. Go back to the Let’s Encrypt certificate page. Select the Issue icon of the Let’s Encrypt cert.

 

kmak_5-1702088948248.jpeg

 

  1. Wait for a couple of minutes for Let’s Encrypt to validate the Domain/FQDN and issue the certificate. Refresh the page and the certificate status shall be updated. Use the troubleshooting guide from Troubleshooting Tip: 'Let's Encrypt' SSL troubleshooting in case if issue fails.

 

kmak_6-1702088948250.jpeg

 

  1. The successfully issued Let’s Encrypt SSL Certificate should show the Domain/FQDN browsing with the certificate as shown.

 

kmak_7-1702088948252.jpeg

 

Related documents:

Let's Encrypt certificates

Troubleshooting Tip: 'Let's Encrypt' SSL troubleshooting

Contributors