Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kianosh
New Contributor

Fortigate Import SSL Certificate Failure

Hi guys, According to my last post, I faced with another problem with Fortigate 300C. when I want to import the generated Certificate into Local Certificates of Fortigate, the Fortigate accept it but it doesn' t show on Certificate list !!! Why??? Please direct me to the right place if you can. Thanks.
6 REPLIES 6
Matthew_Mollenhauer
New Contributor III

My best guess is that you are only uploading the certificate, without any sort of private key. Without a private key you can not use the certificate to do any sort of SSL inspection/encryption. What is the extension of the certificate file you are uploading to the Fortigate? Regards, Matthew Mollenhauer
emnoc
Esteemed Contributor III

Q: 1: Have you tried pasting in via the cli? 2: Have you viewing the full certificate from the cli? show full vpn certificate local note: the above show command will show the private-key 3: next, you can copy the cert/private-key down and validate it with openssl openssl x509 -noout -text -in ./cert openssl rsa -noout -text -in ./key note: make sure to extract the the lines with the data and created 2 files ( cert ) -----BEGIN CERTIFICATE----- -----END CERTIFICATE----- and ( key ) -----BEGIN RSA PRIVATE KEY----- -----END RSA PRIVATE KEY----- https://www.sslshopper.com/certificate-key-matcher.html FWIW, in the past a host of problems exists with the webGUI methods and this has been fix iirc.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Kianosh
New Contributor

Thanks for yor reply Dear emnoc, I' ve created a two Cert.crt and server.key files with OpenSSL tool (two files with .key and .crt extensions) from my Win7 certificate.After import of those files into Fortigate(the Certificate choosing in dropdown list), I' ve not seen the Certificate into Local Certificates List. I' m Confused. Also I check it out with your given website URL. but problem still exist. what can i do to solve it?
emnoc
Esteemed Contributor III

Did you try pasting them in via cli like suggested earlier? What does get vpn certificate local show? What does the show full vpn certificate local show ? Do you have a passphrase installed when you crafted the key ? If yes , can you remove the private-key passphrase?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Kianosh
New Contributor

Hi emnoc, I run your suggested commands and the result as follows : 1- After issue the get vpn certificate local command: # get vpn certificate local == [ Fortinet_Factory ] name: Fortinet_Factory == [ Fortinet_Factory2 ] name: Fortinet_Factory2 == [ Fortinet_Firmware ] name: Fortinet_Firmware == [ Fortinet_CA_SSLProxy ] name: Fortinet_CA_SSLProxy == [ Fortinet_Wifi ] name: Fortinet_Wifi 2- after issue the show full vpn certificate local command, i got all of private keys. 3- yes 4- yes, but is doesn' t work. please give me another solution. Regards, Kianosh [size=3][/size]
emnoc
Esteemed Contributor III

1st I would removed the passphrase 2nd re-upload cert and priv-key 3rd repeat the above steps. 4th re-test the cert+priv-key combo fwiw: I never upload a passphrase

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors