Skip to main content
Staff
July 14, 2026

Technical Tip: Changes in SAML settings after upgrade FortiAuthenticator v8.0.2 version that affects Service Provider

  • July 14, 2026
  • 0 replies
  • 51 views

Description

This article describes changes in SAML settings after upgrading FortiAuthenticator to version v8.0.2 and above, which also affect the Service Provider side.

Scope

FortiAuthenticator.

Solution

After a FortiAuthenticator upgrade to v8.0.2 and above, the next error can occur on the Service Provider side.

Example from FortiManager:

invalid_response: Invalid issuer in the Assertion/Response (expected http://10.10.10.10/saml-idp/7f0y8xpr42juhl92/metadata/, got https://10.10.10.10/saml-idp/7f0y8xpr42juhl92/metadata/).


Or in FortiClient EMS:

FortiClient EAP: Other Error


Here is what changed after the upgrade:

The previous setting for 'IdP entity id' was http.
From this version, it is https:

581b3ae5.png


The solution to fix this error on the Service Provider side is to change the idp-entity-id URL and use https from now on.

Example from FortiGate:

config user saml
    edit <>
        set idp-entity-id "https://10.10.10.10/saml-idp/7f0y8xpr42juhl92/metadata/"
    next
end


Related document:
Resolved Issues 8.02

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!