I have couple of Linux Desktops(Ubuntu 22.04 LTS and Linux Mint LTS versions) that need to use SSO for internet access and other networks. On Fortigate static ip based rules are used for these Linux desktops. These linux desktops are joined to Windows AD thru "sssd" and domain based user login is enabled. However these systems do not show up in FSSO Agent when logged in with AD user name.
FSSO agent mode = DC Agent mode.
On AD, the users are in correct OU and Group.
Are Linux clients supported on FSSO ?.
What are my options to resolve this with other than RSSO or any other Fortinet Products?.
Thanks in Advance,
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Debbie,
Many thanks for these FSSO Agent tips, really appreciate.
I have created "allow_dollar_sign_in_usernames" DWORD and set value to "1" in HKEY_LOCAL_MACHINE\software\wow6432node\fortinet\fsae\collectoragent.
Now DC Agent logs show two entries, first entry with "domain\hostname" and second entry with "domain\username", and the same old 4769 AD events ID. Still linux system not listed on "Show Logon Users" on FSSO agent.
We also see "machine account:<hostname>$ is ignored" entries for windows logins, these are from previous and current DC Agent debug logs.
------------------------------
06/04/2024 12:55:00.553: processing Logon (level=1, logonid=0-0) domain\hostname$ () from (null)
Ignore logon event without workstation information.
06/04/2024 12:55:00.569: finish processing.
Msv1_0SubAuthenticationFilter is called
06/04/2024 12:55:00.694: processing Logon (level=1, logonid=0-0) domain\username (Eby Mani) from (null)
Ignore logon event without workstation information.
06/04/2024 12:55:00.709: finish processing.
Msv1_0SubAuthenticationFilter is called
------------------------------
A Kerberos service ticket was requested.
TargetUserName <hostname>$@<domain>
TargetDomainName <domain>
ServiceName krbtgt/<domain>
ServiceSid S-1-0-0
TicketOptions 0x60000000
TicketEncryptionType 0xffffffff
IpAddress ::ffff:<local ipv4>
IpPort 41842
Status 0xd
LogonGuid {00000000-0000-0000-0000-000000000000}
TransmittedServices -
------------------------------
I will try to integrate ubuntu with winbind, instead of sssd and test if that make any difference.
Thanks,
Hi, I’m interested about this issue because I have the same case to fix. Did you find a solution ?
Found a solution.
On DNS server, manual A record need to be created for linux hosts, else will get “No DNS domain configured for <hostname>. Unable to perform DNS Update.
DNS update failed: NT_STATUS_INVALID_PARAMETER” while joining domain on linux host.
winbind require manual configuration of nsswitch.conf, smb.conf, and krb5.conf files.
On smb.conf, idmap config must use "rid" as backend.
Hope this helps anyone looking to resolve this issue.
Thanks,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1073 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.