Fortinet white logo
Fortinet white logo

CLI Reference

config firewall access-proxy-ssh-client-cert

config firewall access-proxy-ssh-client-cert

Configure Access Proxy SSH client certificate.

config firewall access-proxy-ssh-client-cert
    Description: Configure Access Proxy SSH client certificate.
    edit <name>
        set auth-ca {string}
        config cert-extension
            Description: Configure certificate extension for user certificate.
            edit <name>
                set critical [no|yes]
                set type [fixed|user]
                set data {string}
            next
        end
        set permit-agent-forwarding [enable|disable]
        set permit-port-forwarding [enable|disable]
        set permit-pty [enable|disable]
        set permit-user-rc [enable|disable]
        set permit-x11-forwarding [enable|disable]
        set source-address [enable|disable]
    next
end

config firewall access-proxy-ssh-client-cert

Parameter

Description

Type

Size

Default

auth-ca

Name of the SSH server public key authentication CA.

string

Maximum length: 79

name

SSH client certificate name.

string

Maximum length: 79

permit-agent-forwarding

Enable/disable appending permit-agent-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-port-forwarding

Enable/disable appending permit-port-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-pty

Enable/disable appending permit-pty certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-user-rc

Enable/disable appending permit-user-rc certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-x11-forwarding

Enable/disable appending permit-x11-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

source-address

Enable/disable appending source-address certificate critical option. This option ensure certificate only accepted from FortiGate source address.

option

-

disable

Option

Description

enable

Enable setting.

disable

Disable setting.

config cert-extension

Parameter

Description

Type

Size

Default

name

Name of certificate extension.

string

Maximum length: 127

critical

Critical option.

option

-

no

Option

Description

no

Certificate extension, server ignores the unsupported certificate extension.

yes

Critical option, server refuses to authorize if it cannnot recognize the critical option.

type

Type of certificate extension.

option

-

fixed

Option

Description

fixed

Fixed certificate extension entry.

user

Certificate extension entry filled with authenticated username.

data

Data of certificate extension.

string

Maximum length: 127

config firewall access-proxy-ssh-client-cert

config firewall access-proxy-ssh-client-cert

Configure Access Proxy SSH client certificate.

config firewall access-proxy-ssh-client-cert
    Description: Configure Access Proxy SSH client certificate.
    edit <name>
        set auth-ca {string}
        config cert-extension
            Description: Configure certificate extension for user certificate.
            edit <name>
                set critical [no|yes]
                set type [fixed|user]
                set data {string}
            next
        end
        set permit-agent-forwarding [enable|disable]
        set permit-port-forwarding [enable|disable]
        set permit-pty [enable|disable]
        set permit-user-rc [enable|disable]
        set permit-x11-forwarding [enable|disable]
        set source-address [enable|disable]
    next
end

config firewall access-proxy-ssh-client-cert

Parameter

Description

Type

Size

Default

auth-ca

Name of the SSH server public key authentication CA.

string

Maximum length: 79

name

SSH client certificate name.

string

Maximum length: 79

permit-agent-forwarding

Enable/disable appending permit-agent-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-port-forwarding

Enable/disable appending permit-port-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-pty

Enable/disable appending permit-pty certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-user-rc

Enable/disable appending permit-user-rc certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

permit-x11-forwarding

Enable/disable appending permit-x11-forwarding certificate extension.

option

-

enable

Option

Description

enable

Enable setting.

disable

Disable setting.

source-address

Enable/disable appending source-address certificate critical option. This option ensure certificate only accepted from FortiGate source address.

option

-

disable

Option

Description

enable

Enable setting.

disable

Disable setting.

config cert-extension

Parameter

Description

Type

Size

Default

name

Name of certificate extension.

string

Maximum length: 127

critical

Critical option.

option

-

no

Option

Description

no

Certificate extension, server ignores the unsupported certificate extension.

yes

Critical option, server refuses to authorize if it cannnot recognize the critical option.

type

Type of certificate extension.

option

-

fixed

Option

Description

fixed

Fixed certificate extension entry.

user

Certificate extension entry filled with authenticated username.

data

Data of certificate extension.

string

Maximum length: 127