Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pcguy
New Contributor II

SSL VPN with Client Certificate Authentication

Hi guys,

 

Our company is implementing SSL VPN with Client Certificate which will authenticate by our Fortigate.

However, many of our company users are not able to login with client certificate. Users with administrator rights have no issue to login.

 

The reason is due to these users do not have administrator rights or read permission to access the client certificate's private key. In Windows Group policy, as I know there is no such settings to grant certain read permission to Certificate's private key.

 

Anyone has any experience or encountered the same challenges while do not want to grant administrator rights to normal users?

 

Thanks!

 
1 Solution
pcguy
New Contributor II

We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.

 

Hope can help someone have the same issue.

 

View solution in original post

4 REPLIES 4
boneyard
Valued Contributor

client certificates in the current user store should be accessable without admin rights

pcguy
New Contributor II

boneyard wrote:

client certificates in the current user store should be accessable without admin rights

We are using computer cert as client cert which only accessible by admin rights.

boneyard
Valued Contributor

if you can't change that setup then it wont be possible for regular users.

pcguy
New Contributor II

We found out there is an option in EMS "Allow Non-Administrators to Use Machine Certificates" which totally solved our issue.

 

Hope can help someone have the same issue.

 

Labels
Top Kudoed Authors