- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert."
SSL_VPN/Https/SAMP SP signing Certificate is about to expire. I have been able to import it in our other firewall 1 via the GUI after changing private key format to UTF-8 but I have a difficulty on the other firewall 2 that Im unable to import the certificate and getting this error "Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert."
- 2 FGVM
-FOS 7.0.14
Thank you!
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @martyyy - Are you using signed certificate from the vendor? If so, you can ask them to provide the .pfx file and upload it on FortiGate System>Certificates>Create/Import>Certificate>Import Certificate>Choose PKCS#12 Certificate>Upload.
Ricky
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, If expire certificate is not delete from foritgate and you have update it through cli without generating CSR.
Please click on below link and reference document.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We get an updated cert in PEM format(*.crt) every year. So simply follow the KB to create a new one with slightly different name like "xxxx-2024".
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-a-new-local-certificate-afte...
Toshi
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @rtanagras @Toshi_Esumi ,
Thank you guys for your insights. I managed to import the certificate after rebooting the firewall.
