Integrations

FortiGate Certificate Automation

First-Party Network Target

SSLNexus uses the FortiOS HTTPS REST API through the existing network-target Ansible path. FortiGate generates the private key and CSR; SSLNexus returns only the signed certificate.

Configuration

Workflow

  1. Generate CSR through /api/v2/monitor/vpn-certificate/csr/generate.
  2. Sign through the target CA.
  3. Import the certificate through the local-certificate monitor endpoint.
  4. Update only the selected admin and/or SSL-VPN certificate binding.
  5. Record the appliance relationship for renewal and Dependency & Impact.
Key custody: the private key remains on FortiGate.

Related Documentation

Deployment targets · CA connectors · Dependency & Impact