Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
marliyev
New Contributor

Can not install Root CA cert

Hi,

Cant install CA cert to Fortigate. tried from web and cli. getting from web anf cli difeerent errors.

4 REPLIES 4
emnoc
Esteemed Contributor III

Is the certificate that your installing a rootCA? if you try to intall a non-toot CA as a CA certificate it will fail and error out. Run the cert thru openssl and validate the CA type

 

eg

openssl x509 -in myprivrootCA.cer -noout -text | grep CA

                CA:TRUE

 

This will confirm the cert is not corrupt and also validate that it is a "rootCA"

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
marliyev
New Contributor

hi,

thanx for reply. RootCA is trusted, am using this CA on other machines like Cisco ASA, Router. This CA is openssl based and self-signed. I cant verify on fortigate ca is trusted or not cause ca cert not installed. i want to use ipsec s2s vpn on fortigate using rsa auth, thats why need ca cert.

marliyev

am getting this error from console when copy-paste the ca cert in PEM format:

 

"Input is not a valid CA certificate."

 

same error from web. checked date and time, they are correct.

 

Joey
New Contributor

I'm getting the same issue here, the CA certificate was exported from my FortiAuthenticator

 

I confirmed that my cert is not corrupted and it is a "rootCA" 

Labels
Top Kudoed Authors