FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
rbraha
Staff
Staff
Article Id 223993

Description

 

This article describes how to configure LDAPS with FortiAuthenticator, assuming that the domain controller has a valid computer certificate in place.

 

Scope

 

FortiAuthenticator.

 

Solution

 

In this example, the Microsoft Windows Active Directory has been used as the Certificate Authority,

These tests were performed with Windows Server 2019.

 

Open Run and write mmc.exe,

 

Go to File and select Add/Remove Snap-in, choose Certificates, and select 'Add'.

 

Aashiq_Z_0-1663345988332.png

 

Aashiq_Z_1-1663346014020.png

 

Select the option 'Computer Account'.

 

Aashiq_Z_2-1663346161327.png

 

Select the option 'Local Computer' and chose 'Finish'.

 

Aashiq_Z_3-1663346205512.png

 

Select 'Certificates', go to Personal- Certificates, select the certificate which has the same name as the domain controller (computer certificate).

Right-click, select All task and choose 'Export'.

 

Aashiq_Z_4-1663346265242.png

 

Select the 'No' option, do not export the private key, and DER file format.

 

Aashiq_Z_5-1663346384454.png

 

Specify the name and select 'Next', specify a filename and chose 'Finish'.

 

Aashiq_Z_6-1663346456154.png

 

Import this CA certificate on FortiAuthenticator as Trusted CA.

Go to Certificate Management - > Certificate Authorities - > Trusted CA and select Import.

Specify an ID for the certificate and select upload a file to import the certificate previously exported.

 

10png.png

 

 Go to Authentication -> Remote Auth.Servers -> LDAP, enable the Secure Connection option and select the correct certificate.

 

11.png

 

Try to browse to the directory with LDAPS enabled, which should work fine now.

 

13.png

 

Also, run a packet capture. No readable data should be seen, with only TLS encrypted.

 

12.png