Skip to main content
piaakit1210
New Member
December 12, 2023
Question

Create SAML IDP problem

  • December 12, 2023
  • 3 replies
  • 2000 views

Dear All, 

 

          i was trying to configuring SAML SSO login for ssl vpn with azure ad, i followed below command in fortigate and when i type next, it popup entity-id is empty, and i also have below question in green, any help would be appreicated 

 

 

  1. Create SAML IDP:
    CLI command:
    conf user saml
        edit “azure-name”
    set cert "SSL-VPN settings assigned Server Certificate<-- any ssl cert in fortigate will do ?
      set entity-id "https://<FortiGate IP address or FQDN>:<Custom SSL VPN port>/remote/saml/metadata"

            set single-sign-on-url "https://<FortiGate IP address or FQDN>:<Custom SSL VPN port>/remote/saml/login"
            set single-logout-url "https://<FortiGate IP address or FQDN>:<Custom SSL VPN port>/remote/saml/logout"
            set idp-entity-id "<Azure AD identifier>"  <-- Identifier (Entity ID) from Basic SAML Configuration ?
     
            set idp-single-sign-on-url "<Login URL>"
            set idp-single-logout-url "<Logout URL>"
            set idp-cert "<Certificate imported earlier>"
            set user-name "username"
            set group-name "group"
        next
    end

 

 

 

FortiGate-100F (Azure-name) # next
node_check_object fail! for entity-id is empty.
Attribute 'entity-id' MUST be set.
Command fail. Return code 1

 

piaakit

 

3 replies

dbu
Staff
Staff
December 12, 2023

Hi @piaakit1210 ,

I believe you need to import the SAML IdP Certificate from the Azure. 
And yes that entity-id is set under basic SAML configuration.

Have a look at this guide as it may help with your configuration :

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-SAML-SSO-login-for-FortiGate/ta-p/194656

 

 

ndumaj
Staff
Staff
December 12, 2023
mle2802
Staff
Staff
December 12, 2023

Hi @piaakit1210,

Did you set the command 
config user saml
  set entity-id 

For the "set cert" command, you can the cert assign in SLS VPN setting and the "set idp-entity-id" command is "Azure AD identifier" which be found under step 4 in Azure "Set up FortiGate SSL VPN" not the SAML config.

Regards,
Minh 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!