Shibboleth SSO with Fortigate100F

Axel Philipp Axel.Philipp at biophys.mpg.de
Mon Sep 25 08:52:36 UTC 2023


Hi Peter,

thank you for your answer.

We do not use FortiAuthenticator in our setup and SecurityFabric is not 
configured, too. We did the config under the root domain in "User & 
Authentication" -> "Single Sign On".

This is our current setup on the Fortigate:

FORTIGATE (root) # sh user saml
config user saml
     edit "Biophys-IDP"
         set cert "fortigate_biophys_mpg_de"
         set entity-id "https://<FQDN>/remote/saml/metadata/"
         set single-sign-on-url "https://<FQDN>/remote/saml/login"
         set single-logout-url "https://<FQDN>/remote/saml/logout"
         set idp-entity-id "https://idp.biophys.mpg.de/idp/shibboleth"
         set idp-single-sign-on-url 
"https://idp.biophys.mpg.de/idp/profile/SAML2/Redirect/SSO"
         set idp-single-logout-url 
"https://idp.biophys.mpg.de/idp/profile/SAML2/Redirect/SLO"
         set idp-cert "IDP-BIOPHYS-MPG-DE"
         set user-name "username"
         set group-name "group"
         set digest-method sha1
     next
end

We have tried the settings for the ACS- and SLS-Urls with a trailing '/' 
as well, but it didn't get us any further.

Best regards
Axel Philipp

Axel Philipp
Leiter Zentrale IT
Max-Planck-Institut für Biophysik
Axel.Philipp at biophys.mpg.de
Max-von-Laue-Str. 3, 60438 Frankfurt, Tel: +49 69 6303 4554

On 9/25/23 09:49, Peter Schober via users wrote:
> Axel Philipp <Axel.Philipp at biophys.mpg.de> [2023-09-25 09:33 CEST]:
>> We are trying to connect a Fortigate 100F (OS v7.0.12) to our Shibboleth IDP
>> (4.3.1) to use SAML for SSL VPN authentication. The setup was done according
>> to the Fortinet documentation.
> [...]
>> The Fortigate's debug message says something like 'Name id not found
>> in SAML response' but does not indicate what's missing or wrong.
> What did you configure as the SP's "SAML Attribute"?
> https://docs.fortinet.com/document/fortigate/7.0.12/administration-guide/731053/advanced-option-fortigate-sp-changes
> What "Subject NameID" and "Assertion Attributes" did you configure?
> https://docs.fortinet.com/document/fortigate/7.0.0/new-features/989067/configuring-saml-sso-in-the-gui-7-0-2
>
> -peter

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5432 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20230925/cdeeb18e/attachment.p7s>


More information about the users mailing list