Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
loicgrentzinger
New Contributor II

Forticlient with Machine certificate: force build package to use machine cert without selection

Hi

 

I have packaged a Forticlient Installer. After installing, I'm able to browse the local cert store, but that's not what I want.

I want to package the Forticlient to use and present automatically the machine certificate, without the user to select a certificate or another...

 

I guess it should be an XML option ? Hopefully it will support regex, to be able to select *.domain.com certificate

 

I have foudn this:

<on_os_start_connect>

Enter the name of the VPN tunnel that FortiClient starts when the OS boots up. This tunnel must be configured with <machine> set to 1, with its credentials provided in the XML configuration and stored in HKLM as opposed to HKCU. If using a certificate, the certificate must exist in the computer certificate store.

 

Thanks !

 

 

 

4 REPLIES 4
spoojary
Staff
Staff

I think  Regex isn't supported for certificate selection; specify the exact thumbprint or subject name in the XML.

Siddhanth Poojary
loicgrentzinger

Hi Poojarya and thanks

 

But what's the XML tag to select aan accurate certificate instead of another? I didn't find any option in the XML reference guide.

 

Thanks !

loicgrentzinger
New Contributor II

spoojary
Staff
Staff

Good to know.

Siddhanth Poojary
Labels
Top Kudoed Authors