The error, "SSL server auth flag or digital signature/key encipherment flag is not set in the Certificate", is normally seen when you select the imported local certificate on the Firewall certificate selection Page for firewall management.


If the wrong certificates templates like EPS, Key Recovery Agent, or Exchange user are selected during the validation, this will give us the above-mentioned error message, as these templates support only Encryption and not Digital Signatures.
1. After the CSR request is generated on the firewall, while validating the CSR request on the Internal Server, there would be an option to select the Certificate template and make sure you choose a template as "WebServer", this template supports both Encryption and Digital signatures.

2. Below is the Article for reference which gives detailed information about certificate templates:-
https://forsenergy.com/en-us/certtmpl/html/e6868771-654b-44fd-9853-7cbdd9174f47.htm