I have SAML SSO enabled on the FortiGate using Azure as the IdP, and it's working well.
I'm now trying to enable the SP certificate. I tested several certificates from the FortiGate certificate list, but each one fails with the error:"Signature algorithm used to sign data is not supported."
The IdP metadata shows Azure requires this signature method in SAML metadata:
<SignatureMethod Algorithm="...rsa-sha256" />
How can I generate or issue a certificate on the FortiGate that will produce RSA with SHA-256 signatures via CLI? Please help with CLI commands or steps.
Solved! Go to Solution.
This is a CA certificate. If you have a certificate authority like AD or FortiAuthenticator, you can download it from there and install it on your FortiGate.
This is a CA certificate. If you have a certificate authority like AD or FortiAuthenticator, you can download it from there and install it on your FortiGate.
Makes sense, guess the best option is to import instead of tring to create one fortigate. Thanks.
| User | Count |
|---|---|
| 2677 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.