Why does Fortigate use digital certificates?
For:
How does FortiGate use certificates to identify devices and people?
The subject and subject alternative name fields in the certificate identify the device or person associated with the certificate
How does the revocation check work?
The CRL (certificate revocation list) must be downloaded to Fortigate to use OCSP (online certificate status protocol). Certificates are identified by serial number