Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FloBL
New Contributor

Citrix Access Gateway CHAP

Hi all, We evaluate citrix CAG with fortiauthenticator and remote users (AD via LDAPS). Now we need to allow user to change their expired AD password. If setting CAG RADIUS settings to use CHAP or MS-CHAP1 and 2, fotiauthenticator logs the error: Remote LDAP user authentication(chap) with SMS token failed: remote server supports pap only Thanks for any help.
4 REPLIES 4
Carl_Windsor_FTNT

If setting CAG RADIUS settings to use CHAP or MS-CHAP1 and 2, fotiauthenticator logs the error: Remote LDAP user authentication(chap) with SMS token failed: remote server supports pap only
This is correct behaviour. LDAP Authentication involves sending the password to the server and waiting for a success/fail response. If the authenticating server (CAG in this case) sends CHAP of any form, this is only a hash of the password , not the password itself. Sending this to the LDAP will fail as it will not match. For this reason, the plaintext password (PAP) is required. However, as you are using AD, you have another option. - In your Remote LDAP Config under Authentication > Remote Auth Servers > LDAP configure your AD settings under Windows Active Directory Domain Authentication. - In Authentication > RADIUS Service > Clients, configure GAC to use " All Windows AD users" . - On CAG, set it to send MSCHAP2. By doing this you are telling FortiAuthenticator to skip LDAP authentication and go to AD to compare password hashes.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

FloBL
New Contributor

Hi Carl Thanks a lot for the reply. I have change the settings. Login works direct to AD with mschap but if I set the " user must change password at next logon" flag the user get wrong password answer at CAG logon page and FAC logs: Windows AD user authentication(mschap) with SMS token failed: invalid password I tried mschap and mschap v2. No change. Regards Flo
Carl_Windsor_FTNT

Remote LDAP/AD Password change is currently not supported. Please escalate via your regional Fortinet contact or create a support ticket if this is required and if feasible it can be considered as an NFR.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

FloBL
New Contributor

thanks you for the reply. I have created a ticket and will check with our reseller. Have a nice weekend! Flo
Labels
Top Kudoed Authors