Skip to main content
duenlim
Staff
Staff
May 27, 2022

Technical Tip: 'EVP decryption failed' alert shows in User Event log

  • May 27, 2022
  • 0 replies
  • 1493 views
Description

This article describes why firewall system event logs may show 'FIPS CC decryption failed'.

Scope FortiOS, FIPS-CC mode.
Solution

Example log:

 

date=2022-05-27 time=14:50:49 eventtime=1653634249153306404 tz="+0800" logid="0102038011" type="event" subtype="user" level="alert" vd="root" logdesc="FIPS CC decryption failed" user="admin" ui="GUI(192.168.244.47)" action="decryption" status="failed" msg="EVP decryption failed"

 

The event indicates FortiGate was unable to decrypt and read a local credential. It can have multiple causes, including the following:

  • A GUI bug in older firmware versions when an administrator attempts to update a local user's password by appending characters to the existing password.
  • A misconfigured Kerberos keytab decryption.

 

If the cause is known and expected, the log itself is of no concern.

 

Related articles:

Technical Tip: How to enforce Kerberos keytab with AES256-SHA1 as the used encryption method with Explicit Proxy

Technical Tip: Getting Started with FIPS-CC enabled

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!