Integrations
FortiGate Certificate Automation
First-Party Network Target
SSLNexus uses the FortiOS HTTPS REST API through the existing network-target Ansible path. FortiGate generates the private key and CSR; SSLNexus returns only the signed certificate.
Configuration
- Dedicated REST API token.
- Certificate object name and VDOM/global scope.
- Explicit binding: Admin HTTPS, SSL VPN, both, or certificate object only.
- RSA key size and optional CSR email.
Workflow
- Generate CSR through
/api/v2/monitor/vpn-certificate/csr/generate. - Sign through the target CA.
- Import the certificate through the local-certificate monitor endpoint.
- Update only the selected admin and/or SSL-VPN certificate binding.
- Record the appliance relationship for renewal and Dependency & Impact.
Key custody: the private key remains on FortiGate.

