Fortinet white logo
Fortinet white logo

Examples

Configuring a secret that supports TOTP

Configuring a secret that supports TOTP

This example demonstrates how FortiPAM can be configured to support TOTP.

SSH secrets support TOTP auto-deliviery when launched.

To configure a secret that supports TOTP:
  1. Configuring a secret template with TOTP
  2. Creating a secret with TOTP enabled
Limitations
  1. TOTP auto delivery only supports SSH target and RDP authentication.
  2. TOTP auto delivery for RDP needs the FortiAuthenticator agent running in the target machine and security level set to TLS.
  3. Password changer does not support public key + TOTP authentication.
  4. With TOTP, WebSSH only supports keyboard-interactive authentication method.
  5. With the non-proxy launcher or web launcher, TOTP code must be copied and entered manually.
  6. Do not enable the password changer for the SSH server with password + FortiToken authentication if the username, password, and FortiToken are from another LDAP server.

Configuring a secret that supports TOTP

Configuring a secret that supports TOTP

This example demonstrates how FortiPAM can be configured to support TOTP.

SSH secrets support TOTP auto-deliviery when launched.

To configure a secret that supports TOTP:
  1. Configuring a secret template with TOTP
  2. Creating a secret with TOTP enabled
Limitations
  1. TOTP auto delivery only supports SSH target and RDP authentication.
  2. TOTP auto delivery for RDP needs the FortiAuthenticator agent running in the target machine and security level set to TLS.
  3. Password changer does not support public key + TOTP authentication.
  4. With TOTP, WebSSH only supports keyboard-interactive authentication method.
  5. With the non-proxy launcher or web launcher, TOTP code must be copied and entered manually.
  6. Do not enable the password changer for the SSH server with password + FortiToken authentication if the username, password, and FortiToken are from another LDAP server.