How to Generate a New Self-Signed SSL Certificate

Symptom

Environment

Resolution

Steps

  1. From the WebGUI, navigate to Device > Certificates.

  2. Click Generate at the bottom of the screen.

  3. Enter the desired details for the certificate. The details entered here are what users see if they view the CA certificate for an encrypted session using the browser.

Note: If you would like the certificate to be valid for longer than 365 days (1 year), then please change the "Expiration (days) from 365 to a larger value before creating the certificate.

A screenshot of a computer AI-generated content may be incorrect.

  1. On the Generate Certificate window, click Generate:

A screen shot of a computer AI-generated content may be incorrect.
Certificate successfully generated

  1. To verify that the certificate was created properly, click on the newly generated certificate.

Note: If using this certificate for SSL Decryption, then the options "Forward Trust Certificate" and "Forward Untrust Certificate" are used. It is important to use different certificates as "Forward Trust Certificate" and "Forward Untrust Certificate". The reason for this is that otherwise, hosts will always be presented with a certificate they trust, even when the server presented the firewall with an invalid certificate. For the sake of simplicity both selections are shown below.
To delete or remove the certificate, uncheck both options, otherwise, an error is generated.

Forward trust or untrust selection

  1. Commit the changes. When the commit operation completes, the Self-Signed CA certificate is installed.