I'm trying to test authentication by using Machine certs instead of User certs. When I configure the windows supplicant to use "User or Computer" OR "User" I can authenticate. If I force the setting to "Computer" it fails. Both the computer and user certs are valid and signed by same CA.
I must be missing something in the Radius server config. Any ideas ?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on ā08-02-2024 08:24 AM Edited on ā08-02-2024 08:30 AM
Without the binding, it should work as long as the certificate presented by the supplicant is valid. You can have more information by checking the RADIUS> Authentication debug logs: https://<fac>/debug/
FAC should be root ca for certificate issuing.
What version of FAC is running in this setup? Previous versions, would require certificate bindings with a valid username (hostname). Later version allows also certificate checks only to a Trusted CA:
More information can be found here, Identity source section.
Yes, I have noticed in 6.6 you can use a local or trusted CA instead of bindings. Even when I select the "Trusted CA" option, if the supplicant only sends a Computer cert signed by that particular CA it fails. When the "User or Computer" OR "User", it works. I guess it's not a huge deal because both certs will be present, so why not send both. At this point I'm just curious why.
Created on ā08-02-2024 08:24 AM Edited on ā08-02-2024 08:30 AM
Without the binding, it should work as long as the certificate presented by the supplicant is valid. You can have more information by checking the RADIUS> Authentication debug logs: https://<fac>/debug/
Select Forum Responses to become Knowledge Articles!
Select the āNominate to Knowledge Baseā button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1633 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.