Fortinet white logo
Fortinet white logo

CLI Reference

profile sso

profile sso

Use this command to configure connections with remote authentication servers such as FortiAuthenticator that support single sign-on (SSO) protocols.

In Security Assertion Markup Language (SAML) SSO, you must configure both of these to connect and authenticate with each other:

  • FortiMail, which is the service provider (SP). See system saml.
  • FortiAuthenticator or other remote authentication server, which is the identity provider (IdP)

For details, see the FortiMail SAML SSO workflow.

Syntax

config profile sso

edit <profile_name>

[set comment "<description_str>"]

set remote-user-attribute-name "<attribute_str>"

set idp-metadata <idp-xml_str>

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

comment "<description_str>"

Optional. Enter a description or comment.

idp-metadata <idp-xml_str>

Enter the XML metadata that contains the X.509 server certificate, supported protocols, and service URLs of the identity provider (IdP).

remote-user-attribute-name "<attribute_str>"

Enter the OID of user email addresses on the IdP server.

If you do not enter an OID, then FortiMail uses the default OID urn:oid:0.9.2342.19200300.100.1.3.

Related topics

domain

system admin

system appearance

system saml

profile sso

profile sso

Use this command to configure connections with remote authentication servers such as FortiAuthenticator that support single sign-on (SSO) protocols.

In Security Assertion Markup Language (SAML) SSO, you must configure both of these to connect and authenticate with each other:

  • FortiMail, which is the service provider (SP). See system saml.
  • FortiAuthenticator or other remote authentication server, which is the identity provider (IdP)

For details, see the FortiMail SAML SSO workflow.

Syntax

config profile sso

edit <profile_name>

[set comment "<description_str>"]

set remote-user-attribute-name "<attribute_str>"

set idp-metadata <idp-xml_str>

end

Variable

Description

Default

<profile_name>

Enter a unique name for the profile.

comment "<description_str>"

Optional. Enter a description or comment.

idp-metadata <idp-xml_str>

Enter the XML metadata that contains the X.509 server certificate, supported protocols, and service URLs of the identity provider (IdP).

remote-user-attribute-name "<attribute_str>"

Enter the OID of user email addresses on the IdP server.

If you do not enter an OID, then FortiMail uses the default OID urn:oid:0.9.2342.19200300.100.1.3.

Related topics

domain

system admin

system appearance

system saml