Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
osaleem2_10
New Contributor III

EMS ZTNA Certificate

Hi,

 

I have new deployment project for ZNTA.

 

We have a Local CA. we have generated a CSR from FortiGate and signed it by a local CA to be imported in FortiGate. and for EMS I would like to know what should do for the certificate, as there is no CSR option. Should I only import local CA Root Certificate to EMS server?

 

Kindly need help to understand the certificate required for EMS within local CA and FortiGate.

OSALEEM2_10
OSALEEM2_10
1 Solution
AEK

Yes it should be done before integrating FGT with EMS. This is for good practice integration.

Nevertheless if I remember well (but I'm not sure) there is a command (CLI) on FGT to force accept EMS cert even if it is not trusted, but as you may think this is not recommended for security.

AEK

View solution in original post

AEK
3 REPLIES 3
AEK
SuperUser
SuperUser

Hi Saleem

Under Settings > EMS Server Certificates, you upload certificate (with private key) for both EMS Web server and Endpoint Control. The EMS cert you generate it with its private key on your CA. I usually set its CN to the EMS FQDN, and SAN to EMS IP address (only if needed).

Under Endpoint Policy > CA Certificates, you upload your CA certificate of your Local CA.

Upload the CA certificate on FGT as well so it will trust EMS cert.

AEK
AEK
osaleem2_10
New Contributor III

Thanks for your reply.

 

So, If I have Local CA, I have to generate the Root Cert with Private key to EMS.

 

Just a note, is it mandatory to make this step before integrating with EMS with FortiGate? As i tried to do that, but got an error on FortiGate that EMS cert is not recognized.

 

thanks.

OSALEEM2_10
OSALEEM2_10
AEK

Yes it should be done before integrating FGT with EMS. This is for good practice integration.

Nevertheless if I remember well (but I'm not sure) there is a command (CLI) on FGT to force accept EMS cert even if it is not trusted, but as you may think this is not recommended for security.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors