The issue is observed in versions 6.6.x and 8.0.0, and these are the signs that could lead to FortiToken Mobile not working properly.  Looking specifically at the affected user's tokens would show as Pending in status. A few days later, it was reported that all the PENDING activations had expired, and the users got disabled again.
 Â The error log can be seen below in the access log. Â date=2024-01-22 time=22:14:15+0000 oid=3318835 logid=30909 cat="Event" subcat="System" level="error" nas="" action="" status="" msg="FTM polling error: unable to connect to server: failed to connect fortitokenmobile.fortinet.com:443" user="admin"
 date=2024-01-23 time=01:19:55+0000 oid=3318980 logid=30909 cat="Event" subcat="System" level="information" nas="" action="" status="" msg="FTM polling: try to deprovision expired pending token: FTKMOB0XXXXXXXX" user="admin"
 date=2024-01-23 time=01:19:56+0000 oid=3318981 logid=30909 cat="Event" subcat="System" level="warning" nas="" action="" status="" msg="FTM deprovision: disabled remote LDAP user 'josararai' because FTM activation has expired. Admin must be cautious to re-enable this user because it will be allowed access without token." user="admin"
 To narrow down the issue further, provide the Summary logs to the FortiCare Technical Support. To add an update on the support ticket, log in to the Support portal -> Support -> Manage Active Ticket and check for the ticket number, and provide an update on the ticket.  In this case, the ftmd - FortiToken Mobile daemon process has to be checked further.  Example output from one of the log files in the Summary logs:  Current Processes (by CPU usage)
================================
Mem: 11543216K used, 4838868K free, 1586696K shrd, 1215712K buff, 6782252K cached
CPU: 34.1% usr 0.0% sys 0.0% nic 65.8% idle 0.0% io 0.0% irq 0.0% sirq
Load average: 2.69 2.34 2.26 2/526 2616
PID PPID USER STAT VSZ %VSZ CPU %CPU COMMAND
1692 1 root R 11184 0.0 1 70.0 /bin/ftmd
 In this example, it is found that the ftmd service is stuck or has an unusually high CPU usage percentage.  These symptoms match two known issues: 988000: Bulk de-provisioning of FortiToken Mobiles once FortiToken Mobile servers become reachable if were provisioned when FortiToken Mobile servers were unreachable. 1229968: Possible pending FortiToken Mobile deprovisioning after the FortiToken Mobile application activation due to mishandling of connection termination by the FortiGuard server.
 Workaround : Reboot the FortiAuthenticator, rebooting the FortiAuthenticator. Manually enable users and assign new tokens. When users activate tokens, the status of the tokens will be renewed on FortiAuthenticator.
 Note: The 2 workaround methods noted above do not guarantee that the issue will not happen again.  To prevent issues from happening again, it is recommended to update the FortiAuthenticator to versions 6.6.8 or 8.0.2 as documented in the release notes. Once the token is assigned to a user, it will be pending until the timeout or the user activates the token. In case of failure to send out the token activation code, currently the token remains in a pending state. This timeout is improved in versions 8.0.4 and 8.0.5.
Related documents:
Release notes 6.6.8 Release notes 8.0.2 |