Fortinet white logo
Fortinet white logo

Examples

Creating a secret with check out enabled

Creating a secret with check out enabled

To create a secret with check out enabled:
  1. Go to Secrets > Secret List.
  2. In Secret List, select Create.

    The Create New Secret in: dialog appears.

  3. Select the folder where you intend to add the secret.
  4. Select Create Secret.

    The New Secret window opens.

  5. Enter a name for the secret.
  6. In the Template dropdown, select Unix Account (SSH Password) default template.
  7. In the Fields pane:
    1. In the Host field, enter the IP address or the FQDN of the Linux server.
    2. In the Username field, enter the username for the Linux server.
    3. In the Password field, enter the password for the Linux server.
    4. In the Confirm Password field that appears after the password is filled in, enter the password again.
  8. In the Secret Setting pane:
    1. Ensure that Requires Checkout is enabled.

      Requires Checkout depends on the secret policy applied to the folder where the secret resides.

    2. In Checkout Duration, enter the duration for which the secret is checked out. In this example, Checkout Duration is set to 30 minutes (default).
    3. For added security, enable Checkin Password Change. This allows automatically changing the password when you check in.
    4. If needed, you can enable Renew Checkout and enter the maximum number of renewals allowed in Max Renew Count. This gives you additional exclusive access to the secret. In this example, the Renew Checkout option is disabled.
  9. Click Submit.

Creating a secret with check out enabled

Creating a secret with check out enabled

To create a secret with check out enabled:
  1. Go to Secrets > Secret List.
  2. In Secret List, select Create.

    The Create New Secret in: dialog appears.

  3. Select the folder where you intend to add the secret.
  4. Select Create Secret.

    The New Secret window opens.

  5. Enter a name for the secret.
  6. In the Template dropdown, select Unix Account (SSH Password) default template.
  7. In the Fields pane:
    1. In the Host field, enter the IP address or the FQDN of the Linux server.
    2. In the Username field, enter the username for the Linux server.
    3. In the Password field, enter the password for the Linux server.
    4. In the Confirm Password field that appears after the password is filled in, enter the password again.
  8. In the Secret Setting pane:
    1. Ensure that Requires Checkout is enabled.

      Requires Checkout depends on the secret policy applied to the folder where the secret resides.

    2. In Checkout Duration, enter the duration for which the secret is checked out. In this example, Checkout Duration is set to 30 minutes (default).
    3. For added security, enable Checkin Password Change. This allows automatically changing the password when you check in.
    4. If needed, you can enable Renew Checkout and enter the maximum number of renewals allowed in Max Renew Count. This gives you additional exclusive access to the secret. In this example, the Renew Checkout option is disabled.
  9. Click Submit.