Troubleshooting Tip: Remote LDAPS users fails to connect to SSL VPN with the error unhandled critical extension
| Description | This article describes the issue of being unable to connect to SSL VPN with LDAPS and provides a step-by-step guide to resolve the problem. The user is experiencing issues with authentication due to a certificate validation error. |
| Scope | FortiGate. |
| Solution | Test connectivity with the LDAPS server is successful, but authentication fails when attempting to connect to the VPN.
[1407] __ldap_tcps_connect-Start ldap conn timer.
The issue is related to the server certificate, where certain extensions were marked as critical during the certificate signing process. To resolve this issue, the server certificate must be re-signed with the 'Make this extension critical' option unchecked.
During the certificate signing request generation, Uncheck the 'Make this extension critical'.
After applying the changes described above, the certificate appears as shown below, and users should be able to connect to the SSL VPN successfully.
Related articles: Technical Tip: LDAPS/STARTTLS certificate issuer enforcement |






