Chapter 3 Authentication for FortiOS 5.0 : Users and user groups : Users : PKI or peer users : Creating a peer user
  
Creating a peer user
The configuration page for PKI users in the web-based manager. Follow the CLI-based instructions.
To create a peer user for PKI authentication - CLI example
config user peer
edit peer1
set subject peer1@mail.example.com
set ca CA_Cert_1
end
There are other configuration settings that can be added or modified for PKI authentication. For example, you can configure the use of an LDAP server to check access rights for client certificates. For information about the detailed PKI configuration settings, see the FortiGate CLI Reference.