Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
papapuff
New Contributor II

ask - create client certificate

hi there,

 

need tutorial please.

we use FG-60D, and use vpn ssl for mobile user.

there is setting client certificate. how to create this? We want to make more secure, not only username and password.

 

there is a token, but seems it needs mobile phone or email.

 

thanks in advance

2 REPLIES 2
Christopher_McMullan

Generally speaking, all the FortiGate needs is the CA certificate used to sign the user's certificate. Once you have that (and obviously, have gone through the steps of issuing the client certificate in Windows or otherwise), you're good to go.

 

Import the certificate into the CA section on the FortiGate instead of under Local - that's the key.

 

I've attached a link below Certificate Management How-To document we've used internally and sometimes distributed over the years. It goes through the steps for various scenarios: generating FortiGate certs, having them signed by an enterprise root CA, or by a third-party CA, etc. It should help get you on the right track.

 

https://onedrive.live.com/redir?resid=914DD9934420DA02!251&authkey=!ALLkv-6Rl8yk4Ds&ithint=file%2cdo...

Regards, Chris McMullan Fortinet Ottawa

ziad
New Contributor

Hi all,

 

Need tutorial to for setting sslvpn using client certificate. How to use certificate on forticlient or webportal SSLVPN ? we use FG-90D.

 

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors