



x509 certificate string and save it as a .crt file in X.509 format.| Field | Value |
|---|---|
| Type | Fortinet Product |
| Entity ID | https://ca.auth.kzero.com/tenant/<TENANT_NAME> |
| Assertion Consumer URL | https://ca.auth.kzero.com/tenant/<TENANT_NAME>/protocol/saml |
| Single Logout URL | https://ca.auth.kzero.com/tenant/<TENANT_NAME>/protocol/saml |
| Attribute (Username) | username |
| Attribute (Groups) | groups |


| Field | Value |
|---|---|
| Client ID | https://vpn.example.com/remote/saml/login |
| Valid Redirect URIs (Assertion Consumer Service URL) | https://vpn.example.com/remote/saml/login |
| Field | Value |
|---|---|
| Client ID | https://vpn.example.com/remote/saml/login |
| Name | FortiClient |
| Description | SSO integration |
| Always display in UI | On |
| Field | Value |
|---|---|
| Home URL | https://ca.auth.kzero.com/realms/Randintegration/protocol/saml/clients/forticlient |
| Valid Redirect URIs | https://vpn.example.com/remote/saml/login |
| Valid Post Logout Redirect URIs | https://vpn.example.com/remote/saml/login |
| IDP-Initiated SSO URL Name | forticlient |
| Field | Value |
|---|---|
| Name ID format | username |
| Force POST binding | On |
| Include AuthnStatement | On |
| Field | Value |
|---|---|
| Sign Documents | On |
| Sign Assertions | Off |
| Field | Value |
|---|---|
| Mapper Name | username |
| Mapper Type | User Attribute |
| User Attribute | username |
| SAML Attribute Name | username |
| Field | Value |
|---|---|
| Mapper Name | groups |
| Mapper Type | User Attribute |
| User Attribute | groups |
| SAML Attribute Name | groups |