Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
heretolearn
New Contributor II

LDAPS and Forti products

So I enabled LDAPS on Fortigate, FortiADC, FortiVoice, Fortianalyzer and did NOT upload the RootCA to any of them and LDAP is still working. 

 

For Fortianalyzer I enabled Debugging. So not sure if a cert is required on the fori side of things? 

 

This is what I get with no CERT applied 

2025-11-12 13:16:16 s121: auth request: user= from=GUI
2025-11-12 13:16:16 s121: found admin:
2025-11-12 13:16:16 s121: start ldap: LDAP
2025-11-12 13:16:16 s121:LDAP: connecting to server 0: IPhere ip= port=636/tcp
2025-11-12 13:16:16 s121:LDAP: connected
2025-11-12 13:16:16 s121:LDAP: url: ldaps://IPhere:636
2025-11-12 13:16:16 s121:LDAP: starting tls: ca=
2025-11-12 13:16:16 s121:LDAP: binding admin: FortiSA
2025-11-12 13:16:16 s121:LDAP: got result: Success(0)

 

And here is what I get when a CERT is applied. 

2025-11-12 13:16:16 s121: auth request: user= from=GUI
2025-11-12 13:16:16 s121: found admin:
2025-11-12 13:16:16 s121: start ldap: LDAP
2025-11-12 13:16:16 s121:LDAP: connecting to server 0: HOSTNAMEHERE ip= port=636/tcp
2025-11-12 13:16:16 s121:LDAP: connected
2025-11-12 13:16:16 s121:LDAP: url: ldaps://HOSTNAME:636
2025-11-12 13:16:16 s121:LDAP: starting tls: ca=Root
2025-11-12 13:16:16 s121:LDAP: binding admin: FortiSA
2025-11-12 13:16:16 s121:LDAP: got result: Success(0)

3 REPLIES 3
AEK
SuperUser
SuperUser

If I'm not wrong this requirement is mandatory starting from some late versions.

Which versions of FortiProducts are you using?

AEK
AEK
heretolearn
New Contributor II

Fortigates  7.2.11

Analyzer 7.4.7

ADC 7.4.7

 

AEK
SuperUser
SuperUser

On FGT it is enforced starting from versions 7.4.4.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-LDAPS-STARTTLS-certificate-issuer-enforcem...

On FAZ/FMG/ADC need to search in some release notes.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors