Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aguerriero
Contributor II

Fortiauthenticator 6.6.2 somehow caching duo ldap authentication

This is the setup. I have a SAML front end pointing to a DUO LDAP backend.

(SAML FRONT)FortiAuth(LDAP BACK)  -->  Duo LDAP auth proxy

On previous fortiauth 6.5 if I go to the IDP portal I will get a duo push. Then if I logout the user using the FAC monitor page I will get a duo prompt again when logging in.

https://mydomain.com/saml-idp/portal/

After upgrading to 6.6.2 to fix radius with fortigate 7.2.10, I now have some mysterious caching going on that caches the auth for 24 hours.

Now when I log into a system that uses SAML I get two duo pushes in row and will not be prompted again for another 24 hours. If I log into the fortiauth and make some minor change to the remote authentication LDAP settings like changing the password then saving it, then going back and changing the password back and saving it again, it resets something and I will get the double MFA prompts but only for the very first authentication attempt and it is cached for 24 hours.

Again this setup worked just fine with version 6.5.X. The only difference was upgrading to 6.6.2.



0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors