The Fortinet Fortigate product by default does a MITM attack to deep inspect all SSL and TLS traffic.
Is there a way to create a certificate for a Fortinet device that would allow this? Currently our implementations require installing the self-signed certificate on each computer.
Based on this post, we should probably wait until fortigate supports this.
No, SSL inspection is not possible under the public CA model. You should be researching ways to more easily deploy the root certificate to all your devices, or switching the mode to only block by domain name.
As far as I understand it and how it’s implied in Cisco ASA and/or IOS support the Fortinet Fortigate gateway can be used to intercept traffic to your own site/your own server behind the gateway.
In this case it’s of course possible to intercept the traffic as you own the private key of your webserver.