Good afternoon,
according to SSL certificate shortening, is there possible to NFR customizing ACME provider (GEANT CA), not only Letsencrypt ?
In this time I found that customizing ACME provider in not possible, right ?
FortiWeb ? FortiGate ?
Thanks and best regards
J.Karliak
Hello Josef,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello Josef,
Yes, it is possible to customize the ACME provider on FortiGate to use a service other than Let's Encrypt, such as GEANT CA. However, starting with FortiGate v7.0.2, this option is only available via the CLI. Here are the steps to configure it:
Access the FortiGate CLI.
Enter the following commands to configure the ACME certificate:
config vpn certificate local
edit <certificate_name>
set enroll-protocol acme2
set acme-ca-url <url> # Enter the GEANT CA server/CA URL.
set acme-domain <domain which resolves to FortiGate public IP address>
set acme-email <valid email address>
next
end
Make sure to replace <certificate_name>, <url>, <domain>, and <email> with your specific details.
| User | Count |
|---|---|
| 2806 | |
| 1425 | |
| 812 | |
| 758 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.