Skip to main content
khanhtran
Explorer II
August 23, 2024
Question

Fail to create SSL

  • August 23, 2024
  • 10 replies
  • 6811 views

The secenario is that I was using Forticlient VPN (vpn only version) for remote access. On windows, it works fine with the .crt and .pkf local certificate. However, on Ubuntu, I tried same with those cert and receive a fail to create SSL.

I did research but there was the FortiManagerr and FortiAnalyzer at https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-verify-the-ciphers-used-in-a-PKCS-12/ta-p/327734 but I'm not sure it works the same.

The debug log is as below: 

20240823 09:08:53.049 TZ=+0700 [sslvpn:DEBG] vpn_connection:307 SSL error: error:0308010C:digital envelope routines::unsupported
20240823 09:08:53.049 TZ=+0700 [sslvpn:EROR] vpn_connection:463 Failed parse PKCS#12 file
20240823 09:08:53.049 TZ=+0700 [sslvpn:EROR] vpn_connection:1518 Failed create SSL

 

Anyone that got into such problem and found the way to overcome? Thanks and appreciate any help would come up! 

10 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
August 26, 2024

Hello khanhtran, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser
August 26, 2024

This looks like a SSL version issue.

Please share the following:

  • FortiClient version
  • Linux version ($ cat /etc/os-release)
  • OpenSSL version ($ openssl version)
AEK
khanhtran
khanhtranAuthor
Explorer II
August 26, 2024

FortiClient VPN (vpn only) version 7.2.2 & 7.4.0

Linux Version : Ubuntu 22.04.4

OpenSSL version: OpenSSL 3.0.2 15 Mar 2022 (Library: OpenSSL 3.0.2 15 Mar 2022)

Note:

I tried at config of openssl for the legacy sect to make it default flag for -legacy ( which does overcome the mentioned issue when parsing pkcs#12), however, Forticlient VPN doesn't take effect with that configuration.

AEK
SuperUser
SuperUser
August 26, 2024

Your certificate was generated with legacy provider.

I believe the document your shared should be applicable to FortiClient as well.

https://community.fortinet.com/t5/FortiAnalyzer/Technical-Tip-How-to-verify-the-ciphers-used-in-a-PKCS-12/ta-p/327734

 

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!