13. Fortigate Certificate from Windows CA ADCS(Active Directory Certificate Services)

preview_player
Показать описание
To ignore Warning web page
1. --ignore-certificate-errors
2. Register the unknown certificated to trusted root certification authorities
- AD Server
- Client joined AD
- AD create Certificate
- Client Accept the Certificate from AD
3. If you have money buy a certificate.
4. There is also free certificate only for 3months or 6months
5. Of course, you need to have a domain.

This time I will create a certificate from ADCS and export to Fortigate

Request a Certificate
Submit a certificate request by using a base-64~~~
copy and paste text from a FortiGate self-generated certificate
[-----BEGIN CERTIFICATE REQUEST-----
MIIC0TCCAbkCAQAwYzERMA8GA1UEChMIZG9uZ2hvd2ExETAPBgNVBAsTCGRvbmdo]
download and import [local certificate]
Рекомендации по теме
Комментарии
Автор

thanks for the video, this really helped me

flt
Автор

your video is clear thank you for sharing with us

alisougouma
Автор

Sorry but some errors you made.
1 -when you created CSR on FGT why you didn't use ID Type as a "Domain Name" - you have DN for your AWS FGT. For certs, using the DNs is bettter choice than IP address.
2- Good idea is typing SAN also, as DN and sometimes IP
3 -you don't need a Password for private key - you will not use this cert for signing but only for confirming a fortigate identity in HTTPS protocol
4 - the cert should be indicate in Administrator settings/HTTPS Server certificate, not like you showed in SSL/SSH Inspection, that your configuration isn't succesfull - still is cert error in web browser...

OlafAikido