With Forti Client 7.2.x the connection to LDAP Samba stopped working. From the conversations I have with Fortinet within tickets it seems that they do not intend to fix it. They always refer me to the NFR department. Do you have any solution for this problem? Do we have to slowly prepare to replace FortiClient with some other system?
Hello,
With the EOS coming soon (2025-10-27), has somebody found a solution or a work-around ?
Thanks, Nicolas
I have already lost hope that something will change in this matter and I migrated from Samba to Windows 8 months ago
Hi Tomeks,
after looking at some wireshark trace, it looks like FortiEMS is trying to use Microsoft Sicily LDAP auth mechanism during first negotiation (they call it NTLMSSP, but it is Sicily based, not SASL).
Microsoft Sicily protocol is old and insecure and has been deprecated by Microsoft for quite some time (you can get the NTLM challenge and response in clear if your are not using LDAPS and it is not considered as secure anymore for quite some time).
Microsoft themselves tells not to use that anymore...
Samba does not implement Sicily Auth mechanism as it is obsolete and insecure. But unlike MSAD who will gracefully tell the client that it refuses to negotiate, Samba just drop the connexion.
So Samba is not properly answering to a wrong implementation call from the FortiEMS.
Samba might be too strict and too secure, but FortiEMS shouldn't use that protocol at all and is using unsecure protocols...
We are looking at making Samba answering more gracefully to the Sicily auth negotiation, but it would be great if FortiEMS did fix their unsecure implementation.
Denis
[1] https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/8b9dbfb2-5b6a-497a-a533-7e709c...
[2] https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/e7d814a5-4cb5-4b0d-b408-09d799...
| User | Count |
|---|---|
| 2835 | |
| 1433 | |
| 812 | |
| 793 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.