Hi guys,
Our company is implementing SSL VPN with Client Certificate which will authenticate by our Fortigate.
However, many of our company users are not able to login with client certificate. Users with administrator rights have no issue to login.
The reason is due to these users do not have administrator rights or read permission to access the client certificate's private key. In Windows Group policy, as I know there is no such settings to grant certain read permission to Certificate's private key.
Anyone has any experience or encountered the same challenges while do not want to grant administrator rights to normal users?
Thanks!
Solved! Go to Solution.
We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.
Hope can help someone have the same issue.
client certificates in the current user store should be accessable without admin rights
boneyard wrote:client certificates in the current user store should be accessable without admin rights
We are using computer cert as client cert which only accessible by admin rights.
if you can't change that setup then it wont be possible for regular users.
We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.
Hope can help someone have the same issue.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1739 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.