Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
PampuTV
New Contributor II

FGT export Let's Encrypt certificate

Hi community,

 

I am currently using the Let's Encrypt feature on my FGT (FOS 7.0.4).

Everything is working really good.

I just had the idea to use the FGT as a "certificate hub". So the external FQDN of my NAS points to the FGT WAN IP. This way the FGT can issue a certificate for the external FQDN for my NAS.

Now I am looking into a way to export the issued Let's Encrypt certificate (cert file, key file and passphrase). Found out that the cert file and key file are stored at the FGT and can be exported over the CLI. Sadly, the passphrase is "only" saved encrypted on the CLI (because of security reasons).

To import the Let's Encrypt certificate to my NAS, I need the passphrase unencrypted. 

Any ideas how I could get the encrypted passphrase on the CLI into an unencrypted form?

 

Looking forward for your ideas. Many thanks.


Kind regards

Dominik

 

FortiGate

2 REPLIES 2
AlexC-FTNT
Staff
Staff

Hello Dominik,

It is not possible to obtain the passphrase once a CSR is generated by FortiGate. It was possible in early codes (FortiOS <5.4), but the option is removed due to security reasons.
It is ideal to generate a CSR from a common source like OpenSSL so that the private key file and passphrase are available. Only in this situation, once you get the wildcard signed, you can then use it on more than one device.


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Debbie_FTNT
Staff
Staff

Hey Pampu,

in addition to what Alex mentioned, FortiGate is not intended to act as certificate hub as you described - the CSRs it generates are intended for itself, and no other device.

FortiAuthenticator could act as you're looking for - it can generate CSRs, have them signed by Let's Encrypt or whatever CA of your choice, and then you export the signed certificate and key (once; the key is removed after first export) and provide them to users/machines as desired.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Labels
Top Kudoed Authors