Fortinet black logo

Administration Guide

General

General

As an administrator, you can allow FortiAuthenticator to either automatically sign the user’s certificate or alert you about the request for a signature.

To enable SCEP and configure general settings:
  1. Go to Certificate Management > SCEP > General, and select Enable SCEP.
  2. Configure the following settings:
    Default CAFrom the dropdown, select the default local CA used to issue certificates via SCEP.
    Default enrollment password

    Enter the default enrollment password that is used when not setting a random password.

    Note: You can still choose between the default password or a randomly generated password when creating a new enrollment request.

    Enrollment method

    Select the enrollment method:

    • Automatic: The certificate is pre-approved by the administrator. The administrator enters the certificate information on FortiAuthenticator and gives the user a challenger password to use when submitting their request.
    • Manual and Automatic: The user submits the CSR, the request shows up as pending on FortiAuthenticator unit, then the administrator manually approves the pending request. Optionally, enter an email address to be informed of pending approval notifications.

    Revoke the old certificate on renewal

    Enable to revoke the old certificate after it is renewed.

  3. Select Save to apply any changes you have made.

General

As an administrator, you can allow FortiAuthenticator to either automatically sign the user’s certificate or alert you about the request for a signature.

To enable SCEP and configure general settings:
  1. Go to Certificate Management > SCEP > General, and select Enable SCEP.
  2. Configure the following settings:
    Default CAFrom the dropdown, select the default local CA used to issue certificates via SCEP.
    Default enrollment password

    Enter the default enrollment password that is used when not setting a random password.

    Note: You can still choose between the default password or a randomly generated password when creating a new enrollment request.

    Enrollment method

    Select the enrollment method:

    • Automatic: The certificate is pre-approved by the administrator. The administrator enters the certificate information on FortiAuthenticator and gives the user a challenger password to use when submitting their request.
    • Manual and Automatic: The user submits the CSR, the request shows up as pending on FortiAuthenticator unit, then the administrator manually approves the pending request. Optionally, enter an email address to be informed of pending approval notifications.

    Revoke the old certificate on renewal

    Enable to revoke the old certificate after it is renewed.

  3. Select Save to apply any changes you have made.