PKI user - require specific Application Policy in certificate?
SSL VPN users on a FortiGate can be authenticated with client certificates only, and still checked against LDAP for group membership and enabled status. Or, they can be required to provide a certificate as well as LDAP username and password.
Certificates with the "Smart Card Logon" application policy are on a YubiKey or other smart card & require a PIN with strict attempt limits that lock the card. They are already "something you have" + "something you know" and are considered strong MFA.
User certificates without the "Smart Card Logon" application policy can exist for various other use cases and be stored on laptops and other devices in software. These certs are only worth 1 factor, using one does not prove strong MFA. They chain to the same enterprise root as the smart card certs.
Is there any way to distinguish by application policy, so smart cards can be accepted without the hassle of an LDAP password, without opening it up for weaker-protected certs to be used without MFA?
