FortiSOAR Knowledge Base
FortiSOAR: Security Orchestration and Response software provides innovative case management, automation, and orchestration. It pulls together all of an organization's tools, helps unify operations, and reduce alert fatigue, context switching, and the mean time to respond to incidents.
nmathur
Staff
Staff
Article Id 198736

Description
The "X509 Certificate" used in FortiSOAR™ SSO configuration is expired for versions earlier than 6.4.1. To solve this issue, you need to apply the attached SSO Certificate Script Patch.

 


Solution

To apply the attached SSO Certificate Script Patch, do the following:
  1. Download the attached update_sso_cert.zip file and extract the update_sso_cert.py script file to your FortiSOAR™ system.
  2. Update your FortiSOAR™ Token in the script.
    You can retrieve your token by right-clicking in your browser and clicking Inspect > Elements > Network.
  3. SSH to your FortiSOAR™ VM and run the update_sso_cert.py script as # /opt/cyops-auth/.env/bin/python update_sso_cert.py.
  4. Login to your FortiSOAR™ UI.
  5. Click the Settings icon and then in the "Security Management" section, click Authentication > SSO Configuration
  6. In the "Service Provider" section, in the X509 Certificate field, copy the X509 Certificate.
  7. Go to the ADFS machine and create a new certificate file with contents of the above certificate.
  8. Update this certificate in the following two places in ADFS:
    1. ADFS > Relying Party Trust. Right-click on the specific Relying Party Trust and select Properties and then click on the Encryption tabs as shown in the following image:

      Click Browse and upload the new certificate and then click OK and Apply.
    2. ADFS > Relying Party Trust. Right-click on the specific Relying Party Trust and select Properties and then click on the Signature tab as shown in the following image:

      Select the existing certificate (which is expired) and click Remove. Then, upload the new certificate and click OK and Apply.
  9. Login with SSO from FortiSOAR™.