- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FAC - Wifi EAP-TLS authetication using only Machine certs
I'm trying to test authentication by using Machine certs instead of User certs. When I configure the windows supplicant to use "User or Computer" OR "User" I can authenticate. If I force the setting to "Computer" it fails. Both the computer and user certs are valid and signed by same CA.
I must be missing something in the Radius server config. Any ideas ?
Solved! Go to Solution.
- Labels:
-
FortiAP
-
FortiAuthenticator
Created on ‎08-02-2024 08:24 AM Edited on ‎08-02-2024 08:30 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Without the binding, it should work as long as the certificate presented by the supplicant is valid. You can have more information by checking the RADIUS> Authentication debug logs: https://<fac>/debug/
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FAC should be root ca for certificate issuing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What version of FAC is running in this setup? Previous versions, would require certificate bindings with a valid username (hostname). Later version allows also certificate checks only to a Trusted CA:
More information can be found here, Identity source section.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I have noticed in 6.6 you can use a local or trusted CA instead of bindings. Even when I select the "Trusted CA" option, if the supplicant only sends a Computer cert signed by that particular CA it fails. When the "User or Computer" OR "User", it works. I guess it's not a huge deal because both certs will be present, so why not send both. At this point I'm just curious why.
Created on ‎08-02-2024 08:24 AM Edited on ‎08-02-2024 08:30 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Without the binding, it should work as long as the certificate presented by the supplicant is valid. You can have more information by checking the RADIUS> Authentication debug logs: https://<fac>/debug/
If you have found a solution, please like and accept it to make it easily accessible for others.
