Hello everyone,
I would like to know whether it is possible to generate and create a certificate on FortiMail for internal use for administrators only (ex : internal.example.net). If so, could anyone provide guidance on the process?
Thanks in advance
Best regards,
Hi CL1
To sign a certificate you need a CA.
If you don't have a CA then I think you can use any Linux host to create a private CA with OpenSSL and to sign a certificate for your FML.
Hello AEK,
I currently have a public certificate that all users use, but I would like to set up a separate one exclusively for administrators. Is it possible to configure this on FortiMail? I believe this can be done on FortiGate.
Best regards,
Hi CL1
You need to generate CSR under menu System > Certificate.
Once generated you download it and you sign it with your CA, then you push it again to FortiMail. Once done you should be able use it exclusively for your admin access from the same menu System > Certificate (sorry I don't have a FML lab to provide more details).
Hello AEK,
That's exactly what I'm trying to figure out, how to assign the certificate exclusively for internal use without applying it to public connections. Cause if you go to system > certificat > local certificat, you can only upload the certificate, you can't assign it to a specific use, or can you ? (There is a free Fortimail demo provided by fortinet, but you have "read only" privilege)
Best regards,
Hi Cl1
This doc shows that you can do so.
https://docs.fortinet.com/document/fortimail/7.4.4/administration-guide/383706
Server certificates | FortiMail must present its server certificate when a client requests a secure connection for the:
For details, see Managing local certificates. |
I'll try to test it.
Hello AEK,
Thank you for your answer, I'll try it and see
Kind regards,
I managed to find a lab but I just can't find a solution for your request.
I think opening a ticket will clarify more.
I will try judgeddic solution, and see if it works, if it doesn't I will follow your advice.
Thank you for your usual help
Kind regards,
Yes, you can generate and create a certificate on FortiMail for internal use, such as for administrators accessing an internal domain (e.g., internal.example.net). Below is a step-by-step guide to achieving this:
You have two options:
User | Count |
---|---|
2403 | |
1296 | |
778 | |
542 | |
454 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.