Fortiauthenticator Radius policy - authentication type set to EAP-TLS and mode Certificate Bindings
Hello,
On Fortiauthenticator Radius policy, when authentication type is set to EAP-TLS and authentication mode set to "Certificate Bindings", can a supplicant use user certificate issued by external Trusted root CA like MS AD or issuer has to be FAC's local CA only.
The reason I ask this is because I have user certificate that is signed by third party CA MS AD, when I use "Trusted CA" as authentication mode it works, but if I use "Certificate binding" I get error Certificate chain - 1 cert(s) untrusted.
My intention to use certificate binding as authentication mode is - it gives me an option to do an AD lookup using the relam and use AD group for filtering.
