Fortinet white logo
Fortinet white logo

CLI Reference

profile sso

profile sso

Use this command to configure connections with remote authentication servers such as FortiAuthenticator that support single sign-on (SSO) protocols.

In Security Assertion Markup Language (SAML) SSO, you must configure both of these to connect and authenticate with each other:

  • FortiMail, which is the service provider (SP). See system saml.
  • FortiAuthenticator or other remote authentication server, which is the identity provider (IdP)

For details, see the FortiMail SAML SSO workflow.

Syntax

config profile sso

edit <profile_name>

[set comment "<description_str>"]

set remote-user-attribute-name "<attribute_str>"

set idp-metadata "<idp-xml_str>"

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

comment "<description_str>"

Enter a description or comment.

idp-metadata "<idp-xml_str>"

Enter the XML metadata that contains the X.509 server certificate, supported protocols, and entity ID of the identity provider (IdP).

Tooltip

The metadata must be unique for each SSO profile.

remote-user-attribute-name "<attribute_str>"

Enter the object identifier (OID) of email addresses on the IdP server.

If you do not enter an OID, then FortiMail uses the default OID urn:oid:0.9.2342.19200300.100.1.3.

Related topics

domain

system admin

system appearance

system saml

profile sso

profile sso

Use this command to configure connections with remote authentication servers such as FortiAuthenticator that support single sign-on (SSO) protocols.

In Security Assertion Markup Language (SAML) SSO, you must configure both of these to connect and authenticate with each other:

  • FortiMail, which is the service provider (SP). See system saml.
  • FortiAuthenticator or other remote authentication server, which is the identity provider (IdP)

For details, see the FortiMail SAML SSO workflow.

Syntax

config profile sso

edit <profile_name>

[set comment "<description_str>"]

set remote-user-attribute-name "<attribute_str>"

set idp-metadata "<idp-xml_str>"

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

comment "<description_str>"

Enter a description or comment.

idp-metadata "<idp-xml_str>"

Enter the XML metadata that contains the X.509 server certificate, supported protocols, and entity ID of the identity provider (IdP).

Tooltip

The metadata must be unique for each SSO profile.

remote-user-attribute-name "<attribute_str>"

Enter the object identifier (OID) of email addresses on the IdP server.

If you do not enter an OID, then FortiMail uses the default OID urn:oid:0.9.2342.19200300.100.1.3.

Related topics

domain

system admin

system appearance

system saml