Skip to main content
Carl_Wallmark
New Member
June 18, 2017
Solved

FC 5.6 Shutdown

  • June 18, 2017
  • 8 replies
  • 17539 views

Has anyone managed to shutdown FortiClient 5.6 manually when managed by EMS and you set a password lock ?

 

Even after I click "Disconnect" and enter the password I cannot unlock forticlient and shut it down, works well in 5.4 but not in 5.6.

    Best answer by Carl_Wallmark

    Want to hear some more scary **** ?

     

     

    The GUI in FortiClient is a small webserver, so the functions are plain javascript.

    As a normal user (no admin), take a copy of the forticlient.exe file, put it on your desktop.

    Edit the file with Notepad++

    Because forticlient contains javascript, the functions are in plain text.

    Find the password function. it will be something like this: "if password == password2 then bla bla"

    change the "==" to "!="

    Save the file

    Run it from the desktop, click on disconnect, enter any password you like, BOOM!! accepted and disconnected......

    8 replies

    Carl_Wallmark
    New Member
    June 19, 2017

    I have created a ticket 2239521 if anyone from Fortinet wants to take a look.

    Carl_Wallmark
    New Member
    June 19, 2017

    According to support, this is by design.

     

    It´s impossible to shutdown FortiClient manually when you have configured a "Settings Password" in the EMS profile.

     

     

    FortiMess
    New Member
    July 7, 2017

    This is insane.

     

    Disabling AV completely for a short period of time as a troubleshooting technique to rule out AV as a factor/cause of an end user issue is a L1 task. Disabling AV to uninstall/update AV is also a L1 task (yep, we do this manually since FortiClient's update process is so unbelievably - yet believably, because it's Fortinet - convoluted).

     

    Now we have a setting called "Password Lock Configuration" that does not actually unlock the configuration when you enter the password. Now we have L1 techs who apparently will need access to our AV console, and subsequently (since EMS cannot have multiple local users) either the AV console server or our management domain.

     

    Yesterday a Fortinet rep told me on the phone that they are the leading and de facto information security company. He couldn't see it, but I rolled my eyes. EMS cannot even import a trusted cert, no MITM protection for our AV console?

     

    Industry pioneers? Definitely.

    Enterprise-ready functionality? Not so fast.

     

    Edit: As of v1.2, EMS supports importing a CA-signed cert so you are no longer forced to use the self-signed one that it ships with.

    rejohnson
    New Member
    July 20, 2017

    This works for me with EMS 1.2.1 and FCT 5.6.0.  Create a profile without password lock, apply to a separate group, move computer to that group.  Disconnect.  Can now shutdown FortiClient.

    Carl_Wallmark
    New Member
    July 21, 2017

    Yep, that you can do.

     

    But what do you do when you have someone outside the office, traveling or something that cannot reach your EMS server ?

    Ok, you can of course run FortiClient tools and import a new profile etc. without a password but it´s way more complicated than it should be.

    rejohnson
    New Member
    July 21, 2017

    Evil people make everything more complicated!  I understand that Fortinet has to keep the bad guys from stopping FortiClient but they've probably got this password thing backwards.  If you have a p/w then you should be able to shutdown FortiClient.  No password, then you can't without EMS taking you out of management.

     

    Do you have VPN or publicly publish the EMS server on the Internet?  Definitely need one or both of those if you have remote clients.  If EMS isn't available for other reasons then you're pretty much hosed, anyway.  But I agree that some method of local authentication is still needed because sometimes you just have to be able to shut that sucker down!

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!