Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
cman
New Contributor

SAML SSO -> SP Certificate | Azure IdP

I have SAML SSO enabled on the FortiGate using Azure as the IdP, and it's working well.

 

I'm now trying to enable the SP certificate. I tested several certificates from the FortiGate certificate list, but each one fails with the error:"Signature algorithm used to sign data is not supported."

 

The IdP metadata shows Azure requires this signature method in SAML metadata:

<SignatureMethod Algorithm="...rsa-sha256" />

 

How can I generate or issue a certificate on the FortiGate that will produce RSA with SHA-256 signatures via CLI? Please help with CLI commands or steps.

 

cert1.png

2 REPLIES 2
AEK
SuperUser
SuperUser

This is a CA certificate. If you have a certificate authority like AD or FortiAuthenticator, you can download it from there and install it on your FortiGate.

AEK
AEK
cman
New Contributor

Makes sense, guess the best option is to import instead of tring to create one fortigate. Thanks.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors