Self-signed Root CA Certificate FQDN?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Self-signed Root CA Certificate FQDN?

L3 Networker
I’m planning a test deployment of a globalprotect vpn, so currently going through the guides to see what’s needed. Part of the requirements if not using a trusted CA is to generate a self-signed root CA.

What should the FQDN be on this cert? The deployment will have inside, outside and mgmt interfaces. Should it be the ip on the mgmt interface?
1 REPLY 1

L7 Applicator

Hi @welly_59

 

Do you also plan to implement an internal gateway?

In the root CA cert it does not really matter what you enter as CN. This cert you simply need to install on your computer. As portal and gateway cert you then you need to create another cert which is signed by the previously created root CA cert. In this cert I would use the FQDN or IP of the portal and gateway. Make sure that you also add the same as SAN (server alternative name) to the cert when you create it.

For the management interface cert I recommend to use a different cert than for portal/gateway.

 

Hope this helps,

Remo

  • 1701 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!