Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GregoryK
New Contributor

Eap-tls entra Ad only.

So i was wondering if anyone has this working in production. Trying not to go the captive portal route. Can I achieve this with Fortiauthenticator, If yes what scep client are you using for devices to request their certs? Any input would be appreciated. 

2 REPLIES 2
Jean-Philippe_P
Moderator
Moderator

Hello GregoryK, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Moderator
Moderator

Hello again,

 

Yes, you can achieve EAP-TLS with Entrust AD using FortiAuthenticator. For devices to request their certificates, you can use the Simple Certificate Enrollment Protocol (SCEP) client. FortiAuthenticator acts as a SCEP server, allowing devices to exchange a certificate signing request (CSR) and obtain the signed certificate. Ensure that the SCEP client on the devices is configured to communicate with the FortiAuthenticator's SCEP server.

 

Tell me if it helped you, please :)

Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors