Chapter 3 Authentication for FortiOS 5.0 : Configuring authenticated access : Authentication in security policies : Certificate authentication
  
Certificate authentication
Certificates can be used as part of an identity-based policy. A customized certificate must be installed on the FortiGate unit and in the web browser, which the FortiGate unit will attempt to match.
All users being authenticated against the policy are required to have the proper certificate, which must be imported into the FortiGate unit. See “Certificate-based authentication”.
To require the user to accept a disclaimer to connect to the destination, select Enable Disclaimer. If the user is to be redirected after accepting the disclaimer, enter the URL in the Redirect URL to field. You can edit the User Authentication Disclaimer replacement message text in System > Config > Replacement Messages.