Hi,
following constellation:
We have a FortiGate 100E running here. I created a CSR on it to have that signed by our internal CA. I then imported the certificicate to the fortigate which all worked fine.
I selected it for to use it for https and that works fine so far. It does do https with that cert and I do not get any more Browser warning (since all our clients know our CA).
However the FGT denies me to select that cert for use with SSL Inspection. I can onyl choose the FortiNet built in one here and none of the others installed.
Does anyone have a tip why that is?
FGT runs FortiOS 5.4.x and our CA runs on Wind*ws btw.
FGT is not part of a HA Cluster, a FortiManager or a Fabric..just standalone.
Cheers
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Solved! Go to Solution.
You probably signed the certficate using IIS template or web server template. For SSL decryption it needs to be either CA or SubCA. When you sign it in your CA select the Subordinate certificate authority template. It needs to be a CA/SubCA in order to generate certificates on the fly when decrypting.
Hope that helps
You probably signed the certficate using IIS template or web server template. For SSL decryption it needs to be either CA or SubCA. When you sign it in your CA select the Subordinate certificate authority template. It needs to be a CA/SubCA in order to generate certificates on the fly when decrypting.
Hope that helps
Yeah, thanks for the tip!
That did the trick :) You need to know you need a (sub)CA here. Unfortunately neither the Fortinet Cookbook nor any howto I found on the net mentioned this :(
many cudos to you :)
ty
Sebastian
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Do you know how to do this with openssl?
I only manage to do it with windows server.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.