Description
Since FortiOS 5.4.1, it is possible to use kerberos for authentication as Single-Sign-On (SSO) for the explicit proxy feature.
Since FortiOS 5.6, it is possible to use it for multi-domain environments.
There has been a CLI change to configure the LDAP server that uses kerberos:
1) To use the default name userPrincipalName, or another, like the sAMAccountName.
2) To strip the domain name from the kerberos principal to match the UPN (user PrincipalName).
Solution
Here are the syntax :
Since FortiOS 5.4.1, it is possible to use kerberos for authentication as Single-Sign-On (SSO) for the explicit proxy feature.
Since FortiOS 5.6, it is possible to use it for multi-domain environments.
There has been a CLI change to configure the LDAP server that uses kerberos:
1) To use the default name userPrincipalName, or another, like the sAMAccountName.
2) To strip the domain name from the kerberos principal to match the UPN (user PrincipalName).
Solution
Here are the syntax :
#config user ldap
edit <ldap-server>
set account-key-name <string>
set account-key-processing {same|strip}
next
end
Labels: