If you've spent any time configuring user authentication on... Full Story
By Manny Fernandez
November 26, 2019
FortiAuthenticator as a CA Server
In other articles, I have covered creating CA servers on Microsoft Windows and OpenSSL, here is an article using FortiAuthenticator. FortiAuthenticator or FAC is a versatile solution that can be used for RADIUS, Certificate Authority, 2FA, Guest Portal, BYOD portal.
Stay tuned to the monkey for additional FAC articles. I plan on doing an 802.1x, Guest Portal, 2FA, RADIUS & SSL VPN to name a few.
Creating the CA Certificate
Step 1 – Creating the CA Certificate
First, lets create the CA certificate pair.

- Go to
Certificate Management - Then choose
Certificate Authorities - Choose
Local CAs - Then
Create New
Step 2 – Filling out the Certificate Attributes

- Name the Certificate
- Make sure the
Root CA certificateis selected. - Choose
Field-by-field - Give it the CN (Common Name)
- Fill in the Department
- Fill in the Company Name
- Fill in the City
- Fill in the State
- Choose the correct country.
- Provide an email
- Choose the lifetime for the CA certificate. (3650 days = 10 Years)
- Choose OK.
Step 3 – Export Certificate

- Select the square box on the left of the CA name you created in
Step 2 - Then select
Export Certificate

Step 4 – Validate Correct Format

By NOT selecting the “square box” in step 3 and clicking on the certificate name, you will be able to see the details of the certificate. What you WANT to see is the CA:TRUE
Hope this helps
Recent posts
-
-
DNS is one of those technologies that quietly underpins... Full Story
-
BGP issues on FortiGate firewalls usually trace back to... Full Story
-
Every time your laptop talks to your router, a... Full Story
-
If you've spent any time configuring NAT on a... Full Story
-
If you have spent any time configuring firewall policies... Full Story
-
High availability on FortiGate is one of those features... Full Story
-
If you've configured SD-WAN on a FortiGate, you've almost... Full Story
-
FortiLink is the management protocol that turns a FortiSwitch... Full Story
-
FortiSwitches are pretty rock solid from Mean Time Between... Full Story
-
This is a quicky tip. Have you ever gone... Full Story
-
DNS is one of those quiet pieces of internet... Full Story
-
This article is an updated version of the previous... Full Story
-
You will add ns2 as a secondary (slave) BIND9... Full Story
-
In the process of deploying my lab, I needed... Full Story
-
RFC 8805, used to be known as Self-Correcting IP... Full Story
-
Years back, I wrote an article about certificate pinning. ... Full Story
-
FortiGates have the ability to send alerts to Microsoft... Full Story
-
In this post, I am going to walk through... Full Story
-
Troubleshooting VoIP on a FortiGate can feel like trying... Full Story
-
Prior to FortiOS 7.0, there were three commands to... Full Story
-
In this post, I am going to go over... Full Story
-
What we are going to do: We are going... Full Story
-
Choosing between FGCP (FortiGate Clustering Protocol) and FGSP (FortiGate... Full Story
-
Creating a VLAN on macOS (The "Pro" Move) A... Full Story
-
This blog post explores the logic behind how macOS... Full Story
-
Pretty Fly for a Wi-Fi Tell My Wi-Fi Love... Full Story
-
Part of my daily gig is creating BoMs (Bill-of-Materials)... Full Story
-
ICMP introduces several security risks, but careful filtering, rate... Full Story
-
The command diag debug application dhcps -1 enables full... Full Story
-
In the world of FortiOS, execute tac report is... Full Story
-
LLDP; What is it The Link Layer Discovery Protocol... Full Story
-
What it actually does When you run diagnose fdsm... Full Story
-
Monkey Bites are bite-sized, high-impact security insights designed for... Full Story
-
I have run macOS in macOS with Parallels but... Full Story
-
Don't be confused with my other FortiNAC posts where... Full Story
-
This is the third session in a multi-part article... Full Story
-
Today I was configuring key-based authentication on a FortiGate... Full Story
-
Netcat, often called the "Swiss Army knife" of networking,... Full Story
-
At its core, IEEE 802.1X is a network layer... Full Story
-
In case you did not see the previous FortiNAC... Full Story
-
This is our 5th session where we are going... Full Story
-
Now that we have Wireshark installed and somewhat configured,... Full Story
-
The Philosophy of Packet Analysis Troubleshooting isn't about looking... Full Story
-
If you have ever dug through a drawer full... Full Story
-
In this article, I will cover the basic AC... Full Story
-
OSPF (Open Shortest Path First) is a link-state IGP... Full Story