Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aguerriero
Contributor II

Fortigate 3301E missing API 7.2.11

I have an unusual problem. When I went to add a rest api user I noticed that I am missing options for "REST API Admin" and "SSO Admin". I can only create create system administrators. I have a mix of hundreds of 7.2 and 7.4 systems in my network. This is the only device running 7.2.11 so I dont know if it is specifically for that version. And I cannot downgrade without getting an approved maintenance window.

I tried using the CLI as well...

I cannot type in config system api-user sso-admin... those are missing from the CLI.

API.PNG

 

NO API.PNG

 

1 Solution
Dhruvin_patel

Greetings!

 

The issue you're experiencing with the missing "REST API admin" and "SSO admin" options could be related to the FIPS-CC mode being enabled on your FortiGate device. In FIPS-CC mode, the REST API admin account option is disabled by design.

 

To verify if FIPS mode is enabled, you can use the following command in the CLI:

 

get system status

 

Look for the line, FIPS-CC mode:

 

Regards!

Dhruvin Patel

View solution in original post

3 REPLIES 3
Dhruvin_patel

Greetings!

 

The issue you're experiencing with the missing "REST API admin" and "SSO admin" options could be related to the FIPS-CC mode being enabled on your FortiGate device. In FIPS-CC mode, the REST API admin account option is disabled by design.

 

To verify if FIPS mode is enabled, you can use the following command in the CLI:

 

get system status

 

Look for the line, FIPS-CC mode:

 

Regards!

Dhruvin Patel
aguerriero

That was it. The only other fortigates we have running in FIPS CC are 6 and 7.4.

Dhruvin_patel

I'm glad I could help with your question.

Dhruvin Patel
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors