Dear Forum,
We recently upgraded to fortigate 7.0.1 firmware and we need to use it for SSL purposes for a large number of domain names.
SSL certificates have been already generated and our need is only to upload and configure them through the Fortigate interface.
The following modus operandi works wery well
[ul]
However, this will take a lot of time to secure all our domain names (more than 50).
Is there a faster way to upload and configure several certificates at the same time?
Thank you very much for your attention.
Best regards,
Flavio
Maybe the API but I haven't tried that. You could build a SubjectAlt and list all of the domainNames in the AltName field as a possible solution and specially if your signing your own public-certificates. We did that with entrust and previously with digitrust in a previous role and life.
So we could stroke our own certificates and apply altNames as required and upload the single certificate into the fortigate.
YMMV
Ken Felix
PCNSE
NSE
StrongSwan
Hi Ken,
Thanks a lot for your helpful reply.
We actually find a way to upload multiple certificates through the fortigate API via Terraform. Or at least the API is able to allow this action.
The problem now is that it looks like we can assign only one certificate for VIP address and SNI mode seems not configurable. Do you think that the SAN is the only possible workaround? This latter option is a bit frustrating because we need to generate the certificate again in this case (we have already created 50 crt/key files, namely 1 for each hostname).
Thanks again for your assistance and to everyone may help us.
Best regards,
Flavio
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.