Secure connections and certificates : Replacing the default certificate for the web UI
 
Replacing the default certificate for the web UI
For HTTPS connections with the web UI, FortiRecorder has its own X.509 server certificate. By default, the FortiRecorder appliance presents the “Factory” certificate, which can be used to encrypt the connection, but whose authenticity cannot be guaranteed and therefore may not be trusted by your web browser. This will cause your web browser to display a security alert, indicating that the connection may have been intercepted.
To prevent this false alarm, you can go to System > Certificate > Local Certificate to replace the certificate with one that is signed by your own CA so that it will be trusted. Thereafter, a security alert will only occur if:
the certificate expires
your CA revokes the certificate
the connection has been compromised by a man-in-the-middle attack
If you have not yet requested a certificate from your CA, and if it requires one, you must first generate a certificate signing request (see “Generating a certificate signing request”). Otherwise, start with “Uploading & selecting to use a certificate”.
Table 12: System > Certificate > Local Certificate
Setting name
Description
View
Click to view the selected certificate’s issuer, subject, and range of dates within which the certificate is valid.
Generate
Click to generate a certificate signing request. For details, see “Generating a certificate signing request”.
Download
Click to download the selected certificate’s entry in certificate (.cer), PKCS #12 (.p12), or certificate signing request (.csr) file format. PKCS #12 is recommended if you require a certificate backup that includes the private key.
Certificate backups can also be made by downloading a configuration file backup, which includes all certificates and keys. See “Regular backups”.
Set status
To configure your FortiRecorder appliance to use a certificate, click its row to select it, then click this button. A confirmation dialog will appear, asking if you want to use it as the “default” (currently in use) certificate. Click OK. The Status column will change to reflect the new status.
Import
Click to upload a certificate. For details, see “Uploading & selecting to use a certificate”.
Name
Displays the name of the certificate according to the appliance’s configuration file. This will not be visible to clients.
Subject
Displays the distinguished name (DN) located in the Subject: field of the certificate.
If the row contains a certificate request which has not yet been signed, this field is empty.
Status
Displays the status of the certificate.
Default — Indicates that this certificate will be used whenever a client attempts to connect to the appliance. Only one certificate can be in use at any given time.
OK — Indicates that the certificate was successfully imported. To use the certificate, select it, then use Set status to change its status.
Pending — Indicates that the certificate request (CSR) has been generated, but must be downloaded, signed, and imported before it can be used as a server certificate.
See also
Uploading & selecting to use a certificate
Revoking certificates
Supported cipher suites & protocol versions
Uploading trusted CAs’ certificates