Fortinet white logo
Fortinet white logo

CLI Reference

system sso-admin

system sso-admin

With Single Sign-On Mode enabled, users will be redirected to FortiGate's Single Sign-On Provider page when they click Single Sign-On on FortiWeb's login page. They will be required to log in with FortiGate's administrator account.

Use this command to create a SSO admin account and grant permissions for this account.

For how to configure SSO with FortiGate, see Fabric Connector: Single Sign On with FortiGate.

To use this command, your administrator account’s access control profile must have either w or rw permission to the admingrp area. For details, see Permissions.

Syntax

config system sso-admin

edit <name>

set access-profile <profile name>

set domains <adom name>

end

end

Variable Description Default
<name>

Enter a name of the administrator account, such as admin1 or admin@example.com, that can be referenced in other parts of the configuration.

Do not use spaces or special characters except the ‘at’ symbol ( @ ). The maximum length is 63 characters.

To display the list of existing accounts, enter:

edit ?

Note: This is the user name that the administrator must provide when logging in to the CLI or web UI.

No default
access-profile <profile_name>

Enter the name of an access profile that gives the permissions for this administrator account. See also system accprofile. The maximum length is 63 characters.

You can select prof_admin, a special access profile used by the admin administrator account. However, selecting this access profile will not confer all of the same permissions of the admin administrator. For example, the new administrator would not be able to reset lost administrator passwords.

To display the list of existing profiles, enter:

edit ?

No default
domains <adom_name>

Enter the name of an administrative domain (ADOM) to assign and restrict this administrative account to it.

root

Related topics

system sso-admin

system sso-admin

With Single Sign-On Mode enabled, users will be redirected to FortiGate's Single Sign-On Provider page when they click Single Sign-On on FortiWeb's login page. They will be required to log in with FortiGate's administrator account.

Use this command to create a SSO admin account and grant permissions for this account.

For how to configure SSO with FortiGate, see Fabric Connector: Single Sign On with FortiGate.

To use this command, your administrator account’s access control profile must have either w or rw permission to the admingrp area. For details, see Permissions.

Syntax

config system sso-admin

edit <name>

set access-profile <profile name>

set domains <adom name>

end

end

Variable Description Default
<name>

Enter a name of the administrator account, such as admin1 or admin@example.com, that can be referenced in other parts of the configuration.

Do not use spaces or special characters except the ‘at’ symbol ( @ ). The maximum length is 63 characters.

To display the list of existing accounts, enter:

edit ?

Note: This is the user name that the administrator must provide when logging in to the CLI or web UI.

No default
access-profile <profile_name>

Enter the name of an access profile that gives the permissions for this administrator account. See also system accprofile. The maximum length is 63 characters.

You can select prof_admin, a special access profile used by the admin administrator account. However, selecting this access profile will not confer all of the same permissions of the admin administrator. For example, the new administrator would not be able to reset lost administrator passwords.

To display the list of existing profiles, enter:

edit ?

No default
domains <adom_name>

Enter the name of an administrative domain (ADOM) to assign and restrict this administrative account to it.

root

Related topics