Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Michael_McDonnell
New Contributor III

Yubikey in FAC 4.1?

While exploring FAC 4.1 I just noticed a greyed-out "Yubikey" drop-down menu on the Authentication > User Management > Local Users screen.  Attached is a screenshot with the Yubikey button on the far right side.

 

I do not see a reference to Yubikey support in the new Admin Guide or the release notes. 

 

Is this new to FAC 4.1?

In what way can Yubikey be used with FAC?

Is there FIDO support?

 

5 REPLIES 5
Carl_Windsor_FTNT

This was a special build which was merged into FAC 4.1 at the latter stages and missed being documented.  I will get this rectified ASAP.

 

FortiAuthenticator supports Yubikey USB tokens in OATH-HOTP (Event token) mode.  To import the token seeds into FAC you must create a configuration_log.csv file in Traditional Mode Log Format using the Yubikey Personalization Tool and program the token appropriately.  To use this feature on FAC you must first enable the third party token via https://<FAC_IP>/debug/thirdparty.

 

Dr. Carl Windsor Field Chief Technology Officer Fortinet

Daniel__

Hey so this is a massively old post but I just recently realised the Yubikey is supposed to be supported as a third party, there is still no documentation regarding this at all and following up on your reply Carl, I can import my tokens, I can synchronise them but when I attempt the auth it fails:

 

Message Remote LDAP user authentication with FortiToken failed: invalid token
Name Authentication Failed Bad Token
Description Authentication failed, bad token code

I have obviously set up the user in question with this specific token, it just does not work :)

 

any help would be appreciated

 

 

Carl Windsor wrote:

This was a special build which was merged into FAC 4.1 at the latter stages and missed being documented.  I will get this rectified ASAP.

 

FortiAuthenticator supports Yubikey USB tokens in OATH-HOTP (Event token) mode.  To import the token seeds into FAC you must create a configuration_log.csv file in Traditional Mode Log Format using the Yubikey Personalization Tool and program the token appropriately.  To use this feature on FAC you must first enable the third party token via https://<FAC_IP>/debug/thirdparty.

 

 

Carl_Windsor_FTNT

It was a while ago and I have switch to a new set of products.  Let me ask the new product manager to take a look.

Dr. Carl Windsor Field Chief Technology Officer Fortinet

tanr
Valued Contributor II

Reviving this post (again) since FAC 5.3.1 can still enable the Yubikey support through the debug page listed above.

As I'll be using some Yubikeys for a different project I wondered how they might work with the FortiAuthenticator.

 

Has anyone tried this recently with Yubikeys and FAC 5.3.1 or later?

 

Any official word from Fortinet if this is supported or no longer supported? 

If it's no longer supported it really should be removed.

Daniel__
New Contributor II

I have been trying to get this information myself for a while now, and just like Carl said in an earlier post, only OATH-HOTP is supported, this is super important to understand as it pretty much invalidates a lot of other possibilities, myself I was looking into having the Yubikey authenticate over Azure AD only to find out they only support OATH-TOTP. 

 

And I do not think the development is going at any great rate as even my local representative here knew about the yubikey support

 

right now I am doing a "Chained token authentication with remote RADIUS server" to a Linotp instance for the yubikey+google auth but this requires me to have two servers obviously. 

 

I am seriously thinking of dropping the FortiAuthenticator due to the lock in

Labels
Top Kudoed Authors