Skip to main content
ikmarwright
New Member
May 17, 2022
Question

Certificate errors after applying 6.4.9

  • May 17, 2022
  • 6 replies
  • 10269 views

The error is intermittent since applying 6.4.9 to 6.4.8. The errors appear in FortiClient VPN versions 7.0.1.0083 and 7.0.5.0238. Reinstalling the client software makes no difference. Reinstalling the certificate makes no difference. It is rare, but it is happening to many users.

 

Just starting to track it down, but wondering if anyone else has noticed this.

 

6 replies

xsilver_FTNT
Staff
Staff
May 18, 2022

Hi,

how about to start also with WHAT error do you see?
What is intermittent by your means .. once a year, month, hour ?
Some details on cert like used ciphers and also if signing CA cert was imported to FortiGate.

 

ikmarwright
New Member
May 18, 2022

I wasn't asking for help to narrow it down. I was asking if anyone has seen certificate errors when connecting using SSL VPN after moving to 6.4.9. Obviously you haven't.

 

We only switched to 6.4.9 ten days ago and I've seen three or four errors but the most common is a -11 (The server you want to connect to requests identification, please choose a certificate and try again)

Except there is a validate certificate chosen. And since it actually works the second or third time it's tried, the firewall thinks it's valid too.

 

It's just an OpenSSL certificate that I've used since Nov 2020 without a problem and doesn't expire for another 3 years. 

My focus is elsewhere at the moment, so I was hoping to find out if this a problem for us only or more general. 

 

 

infotechglt
New Member
May 24, 2022

Having the same issue. We don't even use certificate authentication, but it's asking for a certificate now. Only certain users are experiencing this problem. I am not one of them.

jim3cantos
Explorer
June 27, 2022

Same problem here after upgrading from 6.0.14 -> 6.2.10 -> 6.4.8 -> 6.4.9 a few days ago. In our case the error is with Forticlient 6.0.9 and we are using the default Fortinet certificate. It ends up connecting the second or third time it's tried. Only reported by 2 or 3 users but probably happening to more but they don´t complain if they are able to connect after retry...

jim3cantos
Explorer
July 13, 2022

In our case, in the few cases that users still got the error, we implemented this suggestion: "On the Client in IE / Options / Advanced, Turn on TLS 1.2 and TLS 1.3 (and turn off TLS 1.0 and TLS 1.1)" seen in the comments of this page. Not sure if placebo effect or else, but no more complaints from the same users.

jim3cantos
Explorer
July 13, 2022

May be it isn't placebo effect, because it seems that we have solved another synchronization problem with one Outlook mail client (that appeared also after the FortiOS migration) with the same "prescription"...

ikmarwright
New Member
June 27, 2022

Never did figure it out, but after upgrading to 7.0.6 two weeks ago I haven't seen the error.

jim3cantos
Explorer
June 27, 2022

Do you mean FortiOS upgrade to 7.0.6?

ikmarwright
New Member
June 27, 2022

Sorry, yes, I mean FortiOS. I had tried four different 7.X FortiClient versions and it made no difference.