We have successfully configured Fortigate to authenticate SSLVPN users with remote ldap server, using LDAPS from AzureAD.
Now we are trying to implement FortiAuthenticator as we wish to implement MFA
On the FAC, when trying to setup the ldap server, we fail to import the users.
It fails with the following message:
Query failed: ldap_simple_bind_s failed: Can't contact LDAP server error:1416F086:SSL routines:tls_process_server_certificate:certificate verify failed (unable to get local issuer certificate)
I cannot figure out what I need to do. Ldap on Azure requires to run on port 636.
On the FAC, I selected Secure Connection and LDAPS protocol. Somehow I obliged to select one of the built-in FAC CA certificate, which is not required on the Fortigate, and this seems to be the issue.
Has someone an idea of what needs to be done?
Has someone been able to setup a remote LDAP server on FAC using AzureAD LDAPS service?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Not sure it will help, but in my case I had to add my LDAP CA to trusted CAs.
I’m guessing you will need to get the Azure CA certificate, add it to: Certificate Management -> certificate Authorities -> Trusted CAs.
Then Fortiauthenticator must be able to go to internet to check the certificate presented from the Azure LDAP against the CA.
Thanks Ricardo
I added the AzureAD certificate but it did not make a difference
At the moment, I have all outgoing traffic allowed.
For a short period, I also allowed all incoming, to make sure I was not blocking anything but that did not make a difference.
Will try to see if I can help from Fortinet Support. It is a trial version of FortiAuthenticator (we want to test 2FA on multiple Fortigate using AzureAD LDAPS), and I am not sure if Support helps in these cases
Cheers
Did you import only the certificate or did you import the CA chain?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.