Users/peers | Users/peers and user groups |
Delete icon | Delete this PKI peer user. Note: The delete icon is not available if |
| the peer user belongs to a user group. |
Edit icon | Edit this PKI peer user. |
To create a peer user for PKI authentication - CLI
config user peer edit <peer name>
set subject <subject_string> set ca <ca_cert_string>
end
To remove a PKI peer user from the FortiGate unit configuration -
1Go to User > PKI.
2Select the Delete icon beside the name of the PKI peer user that you want to remove.
3Select OK.
Figure 17: Remove PKI peer user
To remove a PKI peer user from the FortiGate unit configuration - CLI
config user peer delete <peer_name>
end
Note: You cannot remove a peer user that belongs to a user group that is part of a firewall policy. Remove it from the user group first.
There are other configuration settings that can be added/modified for PKI authentication, for example, you can configure the use of an LDAP server to check access rights for client certificates. For information about the detailed PKI configuration settings only available through the CLI, see the FortiGate CLI
Reference.
| FortiOS v3.0 MR7 User Authentication User Guide |
38 |