Cleanup of Legacy Authentication CLI to Complete Site Publish Transition (8.0.0)
FortiWeb 8.0.0 finalizes the removal of the legacy authentication framework by clearing all related CLI tables and options. This completes the transition to Site Publishing as the unified mechanism for offloading HTTP authentication and managing user access control.
The previous implementation relied on local user definitions, user groups, authentication rules, and policies. While the associated GUI elements were removed in 7.6.1, backend support remained available through the CLI. In this release, that remaining functionality has now been retired.
CLI Removals in 8.0.0
The following CLI commands and configuration elements have been removed:
|
CLI Path |
Change |
|---|---|
config user local-user
|
Removed |
config user user-group
|
Removed |
config waf http-authen http-authen-rule
|
Removed |
config waf http-authen http-authen-policy
|
Removed |
config waf web-protection-profile inline-protection
|
Removed http-authen-policy |
config waf web-protection-profile offline-protection
|
Removed http-authen-policy (Option already removed in 7.6.1) |
These changes prevent the creation or modification of legacy authentication configurations via the CLI.
Site Publish as the Replacement
All authentication offloading is now handled through Site Publish. This approach supports direct integration with remote authentication servers (LDAP, RADIUS, NTLM, KDC, SAML, and TACACS+) and enables advanced capabilities such as login page customization, two-factor authentication, user attribute forwarding, and optional SSO.
To configure authentication offloading:
-
Define remote authentication servers under User > Remote Server
-
Add the servers to an Authentication Server Pool
-
Create a Site Publish rule that references the pool
-
Apply the rule in a server policy