Skip to main content
systemgeek
Visitor III
April 3, 2024
Solved

Certificate help

  • April 3, 2024
  • 2 replies
  • 1531 views

I am getting lost with all the certs so can someone please help me.  While I have System SAML SSO logins working I noticed that one of the certs involved I have no clue where it came from.  So I am trying to understand which cert is needed where.

 

On the FortiGate:

SAML SSO SP Cert: I am guessing this should be the cert of the SP.  If the SP Address is john.com the cert should be the cert+key of john.com.

SAML SSO IdP cert: This should be the cert of the IdP (imported as a remote cert).  In my case the ADFS server.

 

On the ADFS Server:

Matching Relaying party trust Encryption: ADFS Cert

Matching Relaying party trust Signature: ADFS Cert

 

Does this sound correct?

Best answer by Hong_FTNT

Hi @systemgeek,

 

Yes, it seems correct. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-SSL-VPN-with-ADFS/ta-p/222915

 

Regards, 

2 replies

systemgeek
Visitor III
April 3, 2024

Not being a Windows person it took me a bit to figure out where my extra cert came from.  So I would like to correct the cert listing I have above.

On the FortiGate:

SAML SSO SP Cert: I am guessing this should be the cert of the SP.  If the SP Address is john.com the cert should be the cert+key of john.com.

SAML SSO IdP cert: This should be the cert of the IdP (imported as a remote cert).  In my case the ADFS server Token-decrypoting Cert.

 

On the ADFS Server:

Matching Relaying party trust Encryption: ADFS Service Communication Cert 

Matching Relaying party trust Signature: ADFS Service Communication Cert

 

Hong_FTNT
Staff & Editor
Hong_FTNTAnswer
Staff & Editor
April 4, 2024

Hi @systemgeek,

 

Yes, it seems correct. Please refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-SSL-VPN-with-ADFS/ta-p/222915

 

Regards,