Chapter 3 Authentication for FortiOS 5.0 : Certificate-based authentication : Managing X.509 certificates : Generating certificates with CA software
  
Generating certificates with CA software
CA software allows you to generate unmanaged certificates and CA certificates for managing other certificates locally without using an external CA service. Examples of CA software include ssl-ca from OpenSSL (available for Linux, Windows, and Mac) or gensslcert from SuSE, MS Windows Server 2000 and 2003 come with a CA as part of their certificate services, and in MS Windows 2008 CA software can be installed as part of the Active Directory installation. See “Example — Generate and Import CA certificate with private key pair on OpenSSL”.
The general steps for generating certificates with CA software are
1. Install the CA software as a stand-alone root CA.
2. Provide identifying information for your self-administered CA.
While following these steps, the methods vary slightly when generating server certificates, CA certificates, and PKI certificates.