Hello,
I have strange situation related to my configuration of SSL VPN and LDAP users on my FG100F unit.
Currently all people in my agencies using their LDAP accounts to connect VPN and work remotely.
Last week one person reported to me that it is possible to change expired password using Forticlient.
It is normal because I have configuration which allows to users to change their Windows (LDAP) password.
Unfortunately this user changed password for exactly the same as he had before.
In my GPO I have password history for last 10 and compliance policy on high level (at least 10 characters etc.)
But for now I see that it is possible to change it though Forticlient
Does anyone know how to force FortiGate to use AD policy during password change ?
BR
Konrad
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
This behavior comes from the nature of Windows Server (AD + LDAP). As you have mentioned the authentication and the password reset from FGT/FCT is done while using LDAP, while the password history compliance is pushed through GPO. Technically this password policy is not related at all to the LDAP protocol.
As I know, FGT can not read and interpret GPO restrictions. You can try to find out if Windows Server can apply restrictions for password reset via LDAP to make the reset password procedure fail if an old password is used. This will make the end user to try with a different password next time.
This behavior comes from the nature of Windows Server (AD + LDAP). As you have mentioned the authentication and the password reset from FGT/FCT is done while using LDAP, while the password history compliance is pushed through GPO. Technically this password policy is not related at all to the LDAP protocol.
As I know, FGT can not read and interpret GPO restrictions. You can try to find out if Windows Server can apply restrictions for password reset via LDAP to make the reset password procedure fail if an old password is used. This will make the end user to try with a different password next time.
Hello @ebilcari ,
I will try to find some workaround of this issue
Thank you for you answer!
Konrad
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.