1. Fortinet FortiOS 7.0.1 Handbook - Public Key Infrastructure: In the "Certificate verification" section
it states
"The Authority Key Identifier (AKI) extension in a certificate points to the Subject Key Identifier (SKI) of the certificate that signed it. This allows the FortiGate to build the certificate chain of trust." (p. 21).
2. IETF RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile:
Section 4.2.1.1
"Authority Key Identifier
" explains that this extension identifies the public key used to sign a certificate
typically by referencing the issuer's Subject Key Identifier.
Section 4.2.1.2
"Subject Key Identifier
" defines this extension as a means of identifying certificates that contain a particular public key
which is then referenced by the AKI of certificates it issues.