Skip to main content
IT_DSS
Visitor III
February 26, 2025
Question

Using Authentik radius server - Invalid secret for the server

  • February 26, 2025
  • 4 replies
  • 1981 views

So i recently set up an Authentik radius server 

it works properly as tested by radtest and NTRadPing

 
 

Untitled.png

 Authentik itself also returns "accept" when asked by fortigate

Untitled1.png

 But fortigate refuses to acknowledge that anything is properly configured

 
Untitled2.png

 

debug response:

RTR-032 # diagnose test authserver radius VFX_Authentik pap test test
authenticate 'test' against 'pap' failed, assigned_rad_session_id=103199522320389 session_timeout=0 secs idle_timeout=0 secs!

Does anyone have any idea what could be wrong?

4 replies

AEK
SuperUser
SuperUser
February 26, 2025

Which version is your FortiGate?

Since CVE-2024-3596 fix, FortiOS (7.2.10 & 7.4.5) requires the "Message(Authenticator" attribute. Probably it is not enabled on your RADIUS server.
You can check with diag debug command and try again.

diagnose debug console timestamp enable
diagnose debug application fnbamd -1
diagnose debug enable

 

On case your RADIUS server doesn't support it then try update/upgrade it.

Otherwise there is a workaround in FOS 7.2.11 & 7.4.6 that allows you disable the "Message-Authenticator" attribute.

config user radius
edit rad1
set require-message-authenticator disable
end

Hope it helps.

AEK
IT_DSS
IT_DSSAuthor
Visitor III
February 27, 2025

Unfortunately, neither enabling message-authenticator in Authentik radius (though i'm not sure that worked), nor disabling it in fortigate worked. In the end the fortigate still seems to want it

to be funny, diagnose against pap worked
RTR-032 # diagnose test authserver radius VFX_Authentik pap test test
authenticate 'test' against 'pap' succeeded, server=primary assigned_rad_session_id=106803002163201 session_timeout=0 secs idle_timeout=0 secs!

but testing user credentials in radius settings still doesn't work

IT_DSS
IT_DSSAuthor
Visitor III
February 27, 2025

To be even funnier, even though the testing fails, using vpn with this radius server works O.O, thank you very much for the help

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.