Certificate Templates
API folder: Foundation / Certificate Templates |
The Certificate Templates are used to issue certificates for the IPsec authentication.
To create the Certificate Templates interactively:
-
Go to Device Manager > Provisioning Templates. Under Certificate Templates, click Create New to create two templates named "Edge" and "Hub":
The Certificate Name field (in our example is "Edge" or "Hub") is used for the name of the generated certificate on the FortiGate. Therefore, this name must correspond to the name used in the IPsec configuration. In our case, the IPsec configuration is generated by the Jinja Orchestrator and uses the above names by default.
-
Set Type to Local to use the Certificate Authority (CA) built into FortiManager:
External CA is also supported. This can be a third-party product or FortiAuthenticator. The latter is worth considering, and it can run inside FMG as a Management Extension application (MEA)!
-
Configure the required certificate parameters and save the templates.