Technical Tip: FortiAuthenticator SAML/Portal/API returns error 'Forbidden' and code 403 after upgrade to v6.6.7, and v8.0.0
| Description | This article describes a web service issue that may be encountered after an upgrade to FortiAuthenticator OS v6.6.7, and v8.0.0. |
| Scope | FortiAuthenticator v6.6.7, v8.0.0. |
| Solution | This article applies strictly to upgrades to v6.6.7, v8.0.0, and to web services that worked before the upgrade, including SAML, portal, and API. The end user may see the error below, for example, after a redirection from SP to the IDP (FortiAuthenticator):
This occurs if HTTPS administrator access to the interface providing the web services is disabled. Enabling administrator access would make those services available, but this is not a secure workaround. This will be resolved in the upcoming FortiAuthenticator OS v6.6.8 and v8.0.1. This RSS feed can be followed for the release announcement: https://support.fortinet.com/rss/firmware.xml.
One of the errors that can be seen in FortiAuthenticator's access_logs is as follows:
AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
Note: This is tracked under ID 1223599: SAML authentication redirects to 403 error when 'Web Interface (TCP/443)' access is revoked after upgrading to v6.6.7 and v8.0.0. This issue has been resolved in firmware v6.6.8. |

