Skip to main content
arivet-AMER-FNAC-TAC
Staff
Staff
February 22, 2024

Technical Tip: HTML Characters in RADIUS secret

  • February 22, 2024
  • 0 replies
  • 544 views
Description This article describes why RADIUS secrets that use HTML characters must be saved via the CLI.

 

Unexpected behavior is observed when a RADIUS secret is entered with HTML characters such as the ampersand '&'.

  • Example Radius Secret: 'SuUA01&fTcLkyopnXQ'.
  • What gets saved: 'SuUA01&fTcLkyopnXQ'.


Logs on the devices expecting the correct secret will throw errors such as 'Invalid Authenticator' or 'Bad Secret', even when the user confirms the secret is the same on all devices.

Scope FortiNAC and FortiNAC-F v9.4.X and vF7.2.5.
Solution

Addressed in versions F7.6.0, F7.4.1, and F7.2.7.

 

Workaround:

From the CLI of the device:

 

FortiNAC-OS:

 

execute enter-shell

device -ip <deviceip> -setAttr -name RadiusSecret -value "radiussecret"

 

CentOS:

 

device -ip <deviceip> -setAttr -name RadiusSecret -value "radiussecret"

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!