Description | This article describes one of the causes that crashes SAMLD every time SAML auth is attempted and how can that be fixed. |
Scope |
FortiAuthenticator 6.X, 7.X. |
Solution |
SSL VPN SAML is configured correctly and there is no redirect to the IDP, just the SSL VPN login page timing out at some point.
# diag debug reset ...
Crashlog is showing SAMLD crashing every time a SAML auth is attempted:
# diagnose debug crashlog read ...
Saml connector/user has a ECDSA cert configured like Fortinet_SSL_ECDSA256.
# show user saml
This cert is used to sign SAML messages, and the SAML library used in FortiOS does not support certificates with ECDSA keys.
# config user saml |