Fortinet Introduction
This section refers to the Fortinet integration with Horizon, used to deploy certificates on Fortinet appliances.
This integration involves at least two infrastructure components:
-
A Fortinet FortiGate firewall or a FortiManager appliance
-
EverTrust Horizon
Two connectors are available:
-
The FortiGate connector connects to a single FortiGate firewall using the FortiOS REST API, and deploys certificates in its local certificate store, either in the global scope or in a given virtual domain (VDOM).
-
The FortiManager connector connects to a FortiManager appliance using its JSON-RPC API, and deploys certificates either on the FortiManager unit itself or on a FortiGate device it manages.
Using triggers, Horizon deploys the certificate and its private key on enrollment and renewal, and removes it from the appliance on revocation.
For each holder, only the latest certificate is kept on the appliance: deploying a new certificate removes the previously deployed one. A certificate is only removed if it is still found under the name Horizon gave it; if it was renamed or moved on the appliance, the removal is skipped.
| Only FortiOS 7.0 and later is supported. |