Hi,
I am struggling to find documentation on how to add an internal certificate to the FortiGate HTTPS management page. Every google search returns how to avoid MIM/Webfiltering.
I would like to secure my FortiGate admin logon page with a certificate issued by a Windows PKI server so that the logon page doesn't error when we logon to it.
Any advice or articles to do this would be appreciated!
Tom
-------------------------------------------------
Tom Whiteley Infrastructure Engineer
Solved! Go to Solution.
Simple, bundle the cert+key in pfx format & import it from the WebGUI. Various OSversions has had problems with this btw.
Now, within the global config ; " you set that cert for admin interface"
config system global
set admin-server-cert youcertnamethatyouimport
end
You do not need to reboot the appliance for the certificate to be used
Ken
PCNSE
NSE
StrongSwan
Hi Tom You can also import cert & key directly. Goto System --> Certificates --> Import --> Local Certificate choose Certificate from the dropdown. In System --> Settings choose the imported certificate in Administration Settings Best, Markus
________________________________________________________
--- NSE 4 ---
________________________________________________________
Simple, bundle the cert+key in pfx format & import it from the WebGUI. Various OSversions has had problems with this btw.
Now, within the global config ; " you set that cert for admin interface"
config system global
set admin-server-cert youcertnamethatyouimport
end
You do not need to reboot the appliance for the certificate to be used
Ken
PCNSE
NSE
StrongSwan
Hi Tom You can also import cert & key directly. Goto System --> Certificates --> Import --> Local Certificate choose Certificate from the dropdown. In System --> Settings choose the imported certificate in Administration Settings Best, Markus
________________________________________________________
--- NSE 4 ---
________________________________________________________
Thank you both very much for your advice! I will give that a try :)
-------------------------------------------------
Tom Whiteley Infrastructure Engineer
Can you just not go into the certificates section and import a local certificate of type "certificate" and provide the key file and cert?
I know this is available in 5.4.x, 5.6.x, and 6.0
Thanks everyone - it was as simple as you all said. I was struggling because I wasn't selecting "local certificates" because I didn't realise the term also included "for remote" so I just ignored that option.
I imported my cert and enabled it on the management page. Works a treat!
-------------------------------------------------
Tom Whiteley Infrastructure Engineer
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.