12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CA Certificates<br />

VPN Certificates<br />

Figure 247:CA Certificates list<br />

View Certificate Detail<br />

Download<br />

Import<br />

Name<br />

Subject<br />

Delete icon<br />

View Certificate<br />

Detail icon<br />

Download icon<br />

Import a CA root certificate. See “Importing CA certificates” on<br />

page 376.<br />

The names of existing CA root certificates. The <strong>FortiGate</strong> unit assigns<br />

unique names (CA_Cert_1, CA_Cert_2, CA_Cert_3, and so on) to<br />

the CA certificates when they are imported.<br />

Information about the issuing CA.<br />

Delete a CA root certificate from the <strong>FortiGate</strong> configuration.<br />

Display certificate details.<br />

Save a copy of the CA root certificate to a local <strong>com</strong>puter.<br />

Importing CA certificates<br />

For detailed information and step-by-step procedures related to obtaining and<br />

installing digital certificates, see the <strong>FortiGate</strong> Certificate Management User<br />

<strong>Guide</strong>.<br />

After you download the root certificate of the CA, save the certificate on a PC that<br />

has management access to the <strong>FortiGate</strong> unit.<br />

To import a CA root certificate, go to VPN > Certificates > CA Certificates and<br />

select Import.<br />

Figure 248:Import CA Certificate<br />

SCEP<br />

Local PC<br />

Select to use an SCEP server to access CA certificate for user<br />

authentication. Enter the URL of the SCEP server from which to<br />

retrieve the CA certificate. Optionally, enter identifying information<br />

of the CA, such as the file name. Select OK.<br />

Select to use a local administrator’s PC to upload a public<br />

certificate. Enter the location, or browse to the location on the<br />

management <strong>com</strong>puter where the certificate has been saved,<br />

select the certificate, and then select OK.<br />

When you select OK and you have elected to import a certificate via the SCEP<br />

server, the system starts the retrieval process immediately.<br />

The system assigns a unique name to each CA certificate. The names are<br />

numbered consecutively (CA_Cert_1, CA_Cert_2, CA_Cert_3, and so on).<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

376 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!