profile sso
Use this command to configure connections with remote authentication servers such as FortiAuthenticator that support single sign-on (SSO) protocols.
In Security Assertion Markup Language (SAML) SSO, you must configure both of these to connect and authenticate with each other:
- FortiMail, which is the service provider (SP). See system saml.
- FortiAuthenticator or other remote authentication server, which is the identity provider (IdP)
For details, see the FortiMail SAML SSO workflow.
Syntax
config profile sso
edit <profile_name>
[set comment "<description_str>"]
set remote-user-attribute-name "<attribute_str>"
set idp-metadata <idp-xml_str>
end
|
Variable |
Description |
Default |
|
Enter a unique name for the profile. |
|
|
|
Optional. Enter a description or comment. |
|
|
|
Enter the XML metadata that contains the X.509 server certificate, supported protocols, and service URLs of the identity provider (IdP). |
|
|
|
Enter the OID of user email addresses on the IdP server. If you do not enter an OID, then FortiMail uses the default OID |
|