Manage and validate certificates

This section includes the following topics:

Overview

The FortiADC system is able to process the following two types of TLS/SSL traffic:

The FortiADC system supports all of the TLS/SSL administration methods commonly used by HTTPS servers, including:

Note: The factory certificate is the default certificate for any application over SSL/TSL. It is a unique certificate that presents the credentials of your FortiADC. Upon system start, FortiADC automatically generates a self-signed factory certificate with its identifier (i.e., common name) which is your FortiADC's serial number. For example, if a trial license is in use, then the common name (CN) for the factory.cer would be FADV0000000TRIAL; if the license is imported, the factory.cer would be FADV080000072226.

Certificates and their domains

You can generate or import certificates in the global domain (i.e., FortiADC appliance) and individual VDOM domains (i.e., virtual machines). The visibility and use of certificates or certificate groups may vary, depending where (the domain) they are created. Below are the general guidelines regarding the availability and use of certificates or certificate groups.

Prerequisite tasks

You must download the certificates from your backend servers so that you can import them into the FortiADC system.

This example shows how to download a CA certificate from Microsoft Windows 2003.

To download a CA certificate from Microsoft Windows 2003 Server:
  1. Go to https://<ca-server_ipv4>/certsrv/.
  2. where <ca-server_ipv4> is the IP address of your CA server.

  3. Log in as Administrator. Other accounts may not have sufficient privileges.
  4. The Microsoft Certificate Services home page appears. Figure  57 is an example of this page.

    Figure  57:   Welcome page

  5. Click the Download CA certificate, certificate chain, or CRL link to display the Download a CA Certificate, Certificate Chain, or CRL page. Figure  58 is an example of this page.
  6. From Encoding Method, select Base64.
  7. Click Download CA certificate.

Figure  58:   Download a CA Certificate, Certificate Chain, or CRL page

Manage certificates

This section discusses the following tasks you can perform on the System > Certificate > Manage Certificates page: