Skip to main content
sushantd
Visitor III
January 9, 2025
Question

Fortiauthenticator Radius policy - authentication type set to EAP-TLS and mode Certificate Bindings

  • January 9, 2025
  • 4 replies
  • 1589 views

Hello,

 

On Fortiauthenticator Radius policy, when authentication type is set to EAP-TLS and authentication mode set to "Certificate Bindings", can a supplicant use user certificate issued by external Trusted root CA like MS AD or issuer has to be FAC's local CA only.

 

The reason I ask this is because I have user certificate that is signed by third party CA MS AD, when I use "Trusted CA" as authentication mode it works, but if I use "Certificate binding" I get error Certificate chain - 1 cert(s) untrusted.

 

My intention to use certificate binding as authentication mode is - it gives me an option to do an AD lookup using the relam and use AD group for filtering.

 

 

 

 

4 replies

Debbie_FTNT
Staff & Editor
Staff & Editor
January 9, 2025

Hey Sushantd,

 

FortiAuthenticator can indeed accept supplicant certificates issues by Third-Party CA.

However, for this to work:

 

- you must import the third party CA to FortiAuthenticator under Certificate Management > Certificate Authorities > Trusted CAs

- in the specific user's certificate binding (or user sync rule) you must specify the issuer CA; you can select any CA that is stored under local CA OR trusted CA in FortiAuthenticator

- if there are intermediate CAs between the supplicant's certificate and root CA, I would suggest uploading those as trusted CAs to FortiAuthenticator as well

 

Please let us know if you have any further questions :)

Cheers,

Debbie

sushantd
sushantdAuthor
Visitor III
January 9, 2025

Thank you, Debbie, for your response.

As you recommended, I have imported "Third party CA to FortiAuthenticator under Certificate Management > Certificate Authorities > Trusted CAs".

In the user sync rule, I have specified third party CA that is used to sign the client certificate.

Intermediate CAs are also uploaded to Trusted CA as recommended.

What I see is if authentication mode is set to "Trusted CA" it works as a charm; but if authentication mode is set to "Certificate Binding", FAC reports Certificate chain - 1 cert(s) untrusted.

I can confirm that the Common Name in Subject field is same as one imported from AD. So, not sure what is the problem.

I have raised a TAC Case#10209710 for this but not getting to a conclusion.

 

regards

Sushant

Debbie_FTNT
Staff & Editor
Staff & Editor
January 13, 2025

Hey sushantd,

if there is an intermediate CA in the chain, did you set the trusted root CA in the user sync rule and/or user certificate bindings, or the intermediate one? FortiAuthenticator expects the immediate issuer, not the overall root certificate to be set.

Also, please double-check in the user entry on FortiAuthenticator that the correct CA has been updated in the certificate bindings.

A screenshot of where to find the certificate binding details:

 

image.png

Cheers,

Debbie

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.