config certificate local
Local keys and certificates.
config certificate local Description: Local keys and certificates. edit <name> set type [normal|hsm] set nethsm-slot {string} set password {password} set comments {string} set private-key {user} set certificate {user} set csr {user} set state {user} set scep-url {string} set source [factory|user|...] set auto-regenerate-days {integer} set auto-regenerate-days-warning {integer} set scep-password {password} set ca-identifier {string} set name-encoding [printable|utf8] set source-ip {ipv4-address} set ike-localid {string} set ike-localid-type [asn1dn|fqdn] next end
config certificate local
Parameter |
Description |
Type |
Size |
|||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name |
Name. |
string |
Maximum length: 35 |
|||||||||||
type |
Type. |
option |
- |
|||||||||||
|
|
|||||||||||||
nethsm-slot |
Network HSM slot name. |
string |
Maximum length: 35 |
|||||||||||
password |
Password as a PEM file. |
password |
Not Specified |
|||||||||||
comments |
Comment. |
string |
Maximum length: 511 |
|||||||||||
private-key |
PEM format key, encrypted with a password. |
user |
Not Specified |
|||||||||||
certificate |
PEM format certificate. |
user |
Not Specified |
|||||||||||
csr |
Certificate Signing Request. |
user |
Not Specified |
|||||||||||
state |
Certificate Signing Request State. |
user |
Not Specified |
|||||||||||
scep-url |
SCEP server URL. |
string |
Maximum length: 255 |
|||||||||||
source |
Certificate source type. |
option |
- |
|||||||||||
|
|
|||||||||||||
auto-regenerate-days |
Number of days to wait before expiry of an updated local certificate is requested (0 = disabled). |
integer |
Minimum value: 0 Maximum value: 4294967295 |
|||||||||||
auto-regenerate-days-warning |
Number of days to wait before an expiry warning message is generated (0 = disabled). |
integer |
Minimum value: 0 Maximum value: 4294967295 |
|||||||||||
scep-password |
SCEP server challenge password for auto-regeneration. |
password |
Not Specified |
|||||||||||
ca-identifier |
CA identifier of the CA server for signing via SCEP. |
string |
Maximum length: 255 |
|||||||||||
name-encoding |
Name encoding method for auto-regeneration. |
option |
- |
|||||||||||
|
|
|||||||||||||
source-ip |
Source IP address for communications to the SCEP server. |
ipv4-address |
Not Specified |
|||||||||||
ike-localid |
Local ID the FortiProxy uses for authentication as a VPN client. |
string |
Maximum length: 63 |
|||||||||||
ike-localid-type |
IKE local ID type. |
option |
- |
|||||||||||
|
|