Description | This article describes how to fix and troubleshoot the Winbind integration with FortiNAC. |
Scope | FortiNAC v9.4 and Above |
Solution |
In the scenario below, the Domain Controller Hostname(s) was added as an Asterisk "*", and not as a username Domain Controller Hostname: Multiple servers may be specified, as well as * which will dynamically determine the best DC to contact.
Examples:
"dc01.example.com,dc02.example.com"
Or
"*" Navigate to Network -> RADIUS -> Winbind tab -> keep the service Disabled and select Create New.
Note: The Domain NetBIOS Name must be in upper case, written as 'FORTI'. The same applies to the Kerberos Realm Name.
gse_get_client_auth_token: gss_init_sec_context failed with [Unspecified GSS failure. Minor code may provide more information: Message stream modified](2529638953) To resolve the issue, run the following command on the domain controller FortiNAC is complaining about joining (in this case, it was the secondary domain dc2.forti.lab) to verify the SPN:
Example below:
Go to Windows -> Windows PowerShell on the Domain controller.
PS C:\Users\adminuser> setspn -L FORTI\adminuser A service principal name (SPN) is a unique service instance identifier. Kerberos authentication uses SPNs to associate a service instance with a service sign-in account. fortinac1:~$ cat /etc/samba/smb.conf Result: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.