Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dealer
New Contributor

Cannot generate local certificate

Hi everyone, We recently upgraded our firmware to v5.0,build0228 (GA Patch 4) and now I have discovered that we cannot generate a local certificate. Steps to reproduce are: - Go to - System > Certificates > Local Certificates - Click Generate - Fill in the form with the details shown in the screenshot below When you click OK you get the following error: The imported local certificate is invalid Does anyone know why this is now coming up in error??? regards Aaron.
7 REPLIES 7
NKL
New Contributor III

I opened a ticket on this issue myself. Obviously, it is a known issue, which is due to be fixed with 5.0.5.
emnoc
Esteemed Contributor III

fwiw I generate csr via openssl and then import those into the FGT/FM, less problems and headaches imho

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
dealer
New Contributor

Hi everyone, thanks for the quick response. Just got off the phone with support and they confirmed that it was a known issue and fix was coming in update 5. only problem was that update 5 is scheduled for October sometime. For now going with the workaround from emnoc until they fix the gui.
kcerb
New Contributor III

Hi, I generated a CSR from cli using ' execute vpn certificate local generate' command and the cli returns: ' Generating a 2048 bit RSA private key Generating X.509 certificate Done.' But where is the CSR? Where can I find it?

FGT60B, FGT100A, FGT100D

FGT60B, FGT100A, FGT100D
emnoc
Esteemed Contributor III

Go to GUI >certificates , and you should have CSR that you can download.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
dealer
New Contributor

Hi, if you have update 4 then the CLI won' t generate the local certificate for you. I tried this and while it says " success" it doesn' t actually create the certificate. If you follow the suggestions above and create the certificate externally to the fortigate and then import it you will be ok. I used RapidSSL for this and they will both generate and sign the certificate for you - 2 birds, one website. Otherwise you can just wait until update 5 comes out which will fix this bug.
kcerb
New Contributor III

Thanks for your replays. Yes, I have update 4 and there is no new certificate in GUI after generate. I need a certificate only for internal purpose so I can create it using my active directory integrated CA, it would be easiest because all hosts in my internal network trusts my CA.. But to do so I need a certificate signing request... Or maybe there is another way to create a certificate for fortigate using my CA?

FGT60B, FGT100A, FGT100D

FGT60B, FGT100A, FGT100D
Labels
Top Kudoed Authors