Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Edward-Q
New Contributor

Certificate error when configuring Captive Portal authentication using Azure AD SAML

Hello Fortinet Community,

I’m trying to configure Captive Portal authentication using Azure AD SAML on my FortiGate firewall, but I’m running into a certificate error during the authentication process.

Here’s what I’ve done so far:

  • Imported the Azure AD IdP certificate into FortiGate.
  • Configured the SAML SP settings on FortiGate (Entity ID, SSO URL, Logout URL using public FQDN).
  • Created the user group and enabled Captive Portal on the interface.
  • Policies are in place to allow Azure endpoints without authentication.

Despite this, the login redirect works, but the process fails with a certificate-related error.

Questions:

  • Has anyone successfully resolved this certificate error when using Azure AD SAML for Captive Portal?
  • Do I need to use a publicly signed SSL certificate on FortiGate for the SP URLs?
  • Any tips on matching the certificate requirements between Azure AD and FortiGate?

Any guidance or examples would be greatly appreciated!

0 REPLIES 0
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors