Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tonyagustin
New Contributor II

FortiAuthenticator MFA - SAML

Hello.

We'd like to configure our FortiAuthenticator as SAML IdP. The first authentication factor is password from AD. We've tested several OTP options: fortitoken, sms, email, etc. and the work fine but we'd like to use another second factor: client certificate. We've used local CA or remote CA, and we've configure "certificate bindings" under user configuration, but when SAML web page is shown, it only asks for username and password, and it doesn't prompt to chose a certificate.

Anyone knows if it's possible to configure 2FA with AD password and user certificate?.

Thank you!.

1 Solution
lmarinovic
Staff
Staff

Hello Tony,

 

Unfortunately this is not supported yet. Even if you set certificate bindings on user. This currently can only work for radius. Only second factor under SAML can be:

 

 

Best regards,

 

Lazar

 

Best regards

Lazar Marinovic

View solution in original post

7 REPLIES 7
Stephen_G
Moderator
Moderator

Hello tonyagustin,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Stephen - Fortinet Community Team
Stephen_G
Moderator
Moderator

Hello tonyagustin,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Stephen - Fortinet Community Team
lmarinovic
Staff
Staff

Hello Tony,

 

Unfortunately this is not supported yet. Even if you set certificate bindings on user. This currently can only work for radius. Only second factor under SAML can be:

 

 

Best regards,

 

Lazar

 

Best regards

Lazar Marinovic
pminarik
Staff
Staff

As far as I am aware, this is not currently supported.

Certificate-bindings are used only for EAP-TLS authentication, SAML IdP currently doesn't support client-certificate verification. You'll need a new feature request for this.

[ corrections always welcome ]
tonyagustin
New Contributor II

Thank you all for your answers!

True-i
New Contributor

Dear Sir،,

If you don't mind to share the steps  I need to configure authenticator using saml to login to OWA Mircosoft exchange

Thanks for your support

Rabah35or
New Contributor

Did MFA worked for Exchange AciveSync and AnyWhere ?

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors