Shibboleth SSO with Fortigate100F

Axel Philipp Axel.Philipp at biophys.mpg.de
Mon Sep 25 07:32:42 UTC 2023


Dear List!

If this is not the right place, please refer me to the list where I can 
ask my question.

We are trying to connect a Fortigate 100F (OS v7.0.12) to our Shibboleth 
IDP (4.3.1) to use SAML for SSL VPN authentication. The setup was done 
according to the Fortinet documentation. There are many other (working?) 
examples on the internet for a SAML/SSO connection e.g. to Microsoft 
Azure AD, Google or Keycloak.

A look at the Shibboleth log files shows that everything appears to be 
in order, i.e. after a user is successfully authenticated the IDP sends 
back the attributes (username and group membership) to the Fortigate. 
The Fortigate SSL VPN client appears to log the user in, but eventually 
aborts the login process and returns to the login screen. The 
Fortigate's debug message says something like 'Name id not found in SAML 
response' but does not indicate what's missing or wrong.

We've already verified encoding and encryption parameters on both sides. 
Unfortunately, the vendor support isn't very helpful.

Has anyone successfully set up a Fortigate to use a Shibboleth IDP?

Best regards
Axel Philipp

-- 
Axel Philipp
Leiter Zentrale IT
Max-Planck-Institut für Biophysik
Axel.Philipp at biophys.mpg.de
Max-von-Laue-Str. 3, 60438 Frankfurt, Tel: +49 69 6303 4554

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5432 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20230925/fb85fd19/attachment.p7s>


More information about the users mailing list