Technical Tip: SSL VPN using smartcard certificate with PIN does not work with TLS v1.3 on Windows 11
| Description | This article describes a case where using a smart-card certificate for SSL VPN authentication fails under TLS v1.3 on Windows 11. |
| Scope | FortiClient v7.2.8, v7.2.9. FortiGate v7.4.7. |
| Solution | SSL VPN debug with no client certificate.
2025-07-28 14:16:46 [393:root:142b0]disable RSA-PSS sigalgos.
FortiGate configuration:
kaon-kvm46 # config vpn ssl settings
As a workaround, disable TLS 1.3 and set the max version to TLS v1.2.
config vpn ssl settings |
