Skip to main content
tomeks
New Member
August 2, 2024
Question

Forti Client EMS + LDAP SAMBA

  • August 2, 2024
  • 12 replies
  • 3678 views

With Forti Client 7.2.x the connection to LDAP Samba stopped working. From the conversations I have with Fortinet within tickets it seems that they do not intend to fix it. They always refer me to the NFR department. Do you have any solution for this problem? Do we have to slowly prepare to replace FortiClient with some other system?

12 replies

spoojary
Staff
Staff
August 2, 2024
tomeks
tomeksAuthor
New Member
August 2, 2024

I know this thread. But it ended without solving the problem.

tomeks
tomeksAuthor
New Member
August 5, 2024

So I have another side question. Does anyone still use Samba as AD?

spoojary
Staff
Staff
August 6, 2024

Honestly, it has been a long time I have not seen anyone use it.

informatiquejoskin
Explorer
November 13, 2024

There is still no-one who managed to solve this ?

 

Nicolas

tomeks
tomeksAuthor
New Member
November 13, 2024

Unfortunately I was not able to solve this. I did tests using WireShark and noticed that ldap drops the connection as soon as FortiClient 7.2.x sends the packet "NTLM Message Type: NTLMSSP_NEGOTIATE (1)" version 7.0.x logged in sending "NTLM Message Type: sasl (3)"

Fortinet technical support has given me to understand that they will not do this.

 

I also led discussions on Samba mailing but without result.


[2024/11/05 14:19:11.123630, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'ldapsrv_call_loop: tstream_read_pdu_blob_recv() - NT_STATUS_CONNECTION_RESET'
[2024/11/05 14:19:11.124440, 3] source4/samba/ service_stream.c:67(stream_terminate_connection)
stream_terminate_connection: Terminating connection - 'LDAP_PROTOCOL_ERROR'


When Ems 7.2.x logs in it observes in the Samba logs:

bwesleyNRG
New Member
March 12, 2025

This looks like a very similar problem I struck with using Samba AD authentication for ForiOS after 7.4.4. They hardened the certificate checking requirements for LDAPS and now require the CA signing the certificate on the Samba server to be trusted. I had to import the CA certificate into the Fortigate LDAP config and it fixed the problem.

Here is a Forum post regarding it.
https://community.fortinet.com/t5/Support-Forum/LDAP-authentication-for-admins-not-working-after-FortiOS-7-4-4/td-p/316424

tomeks
tomeksAuthor
New Member
March 12, 2025

The problem with Fortigate is completely different—indeed, it is enough to upload the certificate. In the case of EMS, the issue concerns LDAP protocol support by EMS.

bwesleyNRG
New Member
March 12, 2025

After posting the last reply I did actually try and setup Active Directory in EMS 7.4 with a Samba based DC. This samba dc is currently in production with a Fortigate successfully using it for authentication.  However with EMS it would not work. It was returning en EOF read error. In doing a package trace of the LDAPS handshake it was failing. After sending the initial Hello message. Something around the TLS handshake seems to be the issue. It did work with our Microsoft based DC.  This is very frustrating as we are currently evaluating EMS ZTNA and vpn. I was going to raise a TAC case tomorrow.

 

 

informatiquejoskin
Explorer
July 3, 2025

Hello,

 

With the EOS coming soon (2025-10-27), has somebody found a solution or a work-around ?

 

Thanks, Nicolas

tomeks
tomeksAuthor
New Member
August 20, 2025

I have already lost hope that something will change in this matter and I migrated from Samba to Windows 8 months ago

dcardon
New Member
December 4, 2025

Hi Tomeks,

after looking at some wireshark trace, it looks like FortiEMS is trying to use Microsoft Sicily LDAP auth mechanism during first negotiation (they call it NTLMSSP, but it is Sicily based, not SASL). 

Microsoft Sicily protocol is old and insecure and has been deprecated by Microsoft for quite some time (you can get the NTLM challenge and response in clear if your are not using LDAPS and it is not considered as secure anymore for quite some time).

Microsoft themselves tells not to use that anymore...

Samba does not implement Sicily Auth mechanism as it is obsolete and insecure. But unlike MSAD who will gracefully tell the client that it refuses to negotiate, Samba just drop the connexion. 

So Samba is not properly answering to a wrong implementation call from the FortiEMS.

Samba might be too strict and too secure, but FortiEMS shouldn't use that protocol at all and is using unsecure protocols...

 

We are looking at making Samba answering more gracefully to the Sicily auth negotiation, but it would be great if FortiEMS did fix their unsecure implementation.

 

Denis 

 

[1] https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/8b9dbfb2-5b6a-497a-a533-7e709cb9a982
[2] https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/e7d814a5-4cb5-4b0d-b408-09d79988b550

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!