FortiGate and kerberos authentication to explicit proxy
I' trying to configure kerberos so clients can use this to authenticate to the explicit web proxy. The release notes talk about this very briefly, but cannot find any info on what steps need to be taken to configure this. The first is pretty self-explanatory and can also be configured from GUI. But the second, where we need to configure the account in the AD which is mapped to the SPN is not.
- Where do I for example get the base64 encoded keytab?
- Is the LDAP server the profile name that can be configured in the GUI, or do I need to specify a host name?
I guess as this feature is quite new Fortinet hasn't gotten around to describe it in more detail yet. Can someone provide the steps to do this?
Support Kerberos and NTLM authentication (370489)
FortiGate now recognizes the client's authentication method from the token and selects the correct authentication scheme to authenticate successfully.
CLI syntax
config firewall explicit-proxy-policyedit <example>set active-auth-method [ntlm | basic | digest | negotiate | none]endExplicit web proxy Kerberos authentication support (297503)
The following web proxy Kerberos authentication CLI syntax has been added:
