Skip to main content
goldfinger
New Member
August 27, 2018
Question

SSL VPN single sign-on using LDAP-integrated certificates with iPhones/iPads

  • August 27, 2018
  • 1 reply
  • 2911 views

 

Hi,

currently we use a Fortinet 500D with version 5.6 for SSL-VPN.

We have two VDOMs

VDOM root (for the old world, IP Sec and local accounts) VDOM1 (for a new AD environment SSO)

In the VDOM1 environment we use a computer certificate to establish a connection. No user authentification is required at this time. The Fortinet 500D looks at the upn of the computer object in AD and if it is matching the computer will grant access based on his group membership. This is working very well.

(Tunnel mode and split tunneling is on. No using of scep or Fortinet Authenticator) https://cookbook.fortinet...tegrated-certificates/

 

But now we got some iPhones/iPads and we can't integrate it in the same way.

We configured it in the following manner: - We installed the FortiClient 5.6.6 on this IOS devices. - We installed the device certificate for the fortinet client and see it. - We created dummy AD iOS computer objects with the upn/dns attribute. - We omit the username/password on the FortiClient configuration wizard. => The configuration above is not working as expect because we don't get a connection.

 

It seems that the ldapmode pincipal-name is a bad idea together with iPhones/iPads. Perhaps they should get access if the certificate itself is OK and without  upn matching.

How can we integrate this device group with vpn-ssl and certificates? Do we need a third VDOM?

1 reply

goldfinger
New Member
September 3, 2018

Solved. The problem was on the Fortinet VPN-Client side. The certificate has a wrong extension .pfx instead of .p12

By installing the certification path via email method there was no question about the secret to install. With iTunes and entering the secret in the passphrase we get a connection.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!