Skip to main content
ndespres
New Member
June 10, 2020
Question

Error "get_ha_sync_obj_sig_4dir" in new HA setup

  • June 10, 2020
  • 4 replies
  • 6692 views

Hi all, new to this world after a decade of supporting and managing Sonicwalls. Done a few smaller setups of Fortigate 60E's, but this is my first big one, setting up a new HA pair of 400E's in active/passive setup. I updated firmware on both devices to FortiOS v6.4.1 build1637 (GA) and am now repeatedly getting this error in the console of the master unit, whenever the secondary unit is online. The error does not appear in the console of the secondary unit.


get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2
get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/5c44d531.0 error 2
get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/157753a5.0 error 2

 

HA status in the GUI looks normal.

 

Can you please help me work through how to troubleshoot and resolve this issue? I'm struggling to find a command that lets me see what these certificates are, or what "error 2" is. I haven't loaded any of my own certificates yet.

 

Thanks in advance for your help!

4 replies

Statista
New Member
June 16, 2020

same Problem here with ticket Number: 4105192

tried in different ways, always with the same result -.-

Statista
New Member
June 16, 2020

because nobody of the support team could really help me i have solved the problem "qiuck & dirty". Compare Backup of Master & slave FGT. Change the Master Backup to restore to slave FGT. the following must be changed: hostname ha device priority

MichaelA1
New Member
August 19, 2020

I was seeing them as well on multiple clusters.  I was just preparing to update one of the clusters to 6.4.2 and saw this in the console:

 

get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/5c44d531.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/157753a5.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/def36a68.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/c0ff1f52.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2

but after the upgrade, I saw this on the console of the original master just after it came online after the reboot.

get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/988a38cb.0 --> /etc/cert/ca/root_NetLock_Arany_(Class_Gold)_Főtanúsítvány.cer get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/5c44d531.0 --> /etc/cert/ca/root_Staat_der_Nederlanden_Root_CA_-_G2.cer get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/157753a5.0 --> /etc/cert/ca/root_AddTrust_External_Root.cer

 

I have been debugging/watching the console, no more errors.  Maybe they added a root cert cleanup?  I have not scrubbed the full release notes but...

kichitan
Staff
Staff
December 21, 2021

Bug was solved on version 6.4.2

 

https://docs.fortinet.com/document/fortigate/6.4.2/fortios-release-notes/289806/resolved-issues

 

Check under HA bus number 639307

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!