Certificate path configuration for automated certificate selection
The EMS administrator can configure a certificate location in a Remote Access profile for SSL and IPsec VPN. FortiClient (Android) automatically goes to the certificate location when doing the following:
- When selecting a certificate
- When the user clicks Connect to connect to SSL VPN
To configure certificate path for automated certificate selection:
- In EMS, go to Endpoint Profiles > Remote Access.
- Create a new profile or edit an existing one.
- Click Add VPN Tunnel.
- Do one of the following:
- For an SSL VPN tunnel, enable Require Certificate.
- For an IPsec VPN tunnel, from the Authentication Method dropdown list, select Smart Card Certificate or System Store Certificate.
- In the Android Certificate Location field, enter the certificate location for the Android device. In this example, the location is certdir/. You should already have created this directory in the Android device internal storage. The certificate path can be only one level deep.
- Connect FortiClient (Android) to EMS.
- After FortiClient (Android) receives the configuration changes, do the one of the following:
- For SSL VPN, connect to VPN. Clicking Connect automatically navigates to certdir, the configured certificate location. Clicking the certificate options in Settings for the VPN tunnel also goes to sslcertdir.
- For IPsec VPN, go to the tunnel, then Settings > Server settings > Certificate. FortiClient (Android) automatically navigates to certdir, the configured certificate location. Select the certificate, enter the password, then click Connect. The tunnel establishes successfully.