Skip to main content
j_pepin
New Member
March 26, 2021
Question

Certificate authentication error

  • March 26, 2021
  • 0 replies
  • 2105 views

Hi all,

I have a problem when setting up authentication via certificate.

 

We operate with a root certification authority which signs an intermediate certification authority.

It is then this intermediate CA which is imported into Fortigate and which signs the client certificates.

When I import the intermediate CA on the fortigate and I connect via a client certificate signed by this same authority, it works.

However, when restarting the firewall, the ERR_BAD_SSL_CLIENT_AUTH_CERT error occurs.

Unable to reconnect with the certificate that was working before reboot.

If I import the root CA and connect with a client certificate signed by that authority, it works even after a reboot.

 

I conclude that the problem is with the intermediate CA but I cannot put my finger on what is wrong.

Has anyone ever had the problem?

 

For information, I am on a 50E in 5.6.13. But I did the same tests on other versions and other models. The problem is the same.

 

Thank you for your help.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!