FortiClient 5.6.2 IPsec-VPN with certificate authentication
Hi!
We are trying to configure FortiClient to VPN to our Fortigate with certficate authentication.
We deploy Forticlient Profiles with a trial Version of EMS 1.2.2
The configuration of the Fortigate seems to be ok. IPSec-VPN with preshared key works and IPsec-VPN with certificate authentication using a certificate in the user-store works also, if I manually create the vpn on the FortiClient.
But if I deploy a VPN in the FortiClient-Profile created in EMS, the VPN connection failes with the following error in FortiClient.log:
22.11.2017 17:42:55 Fehlersuche VPN AuthDaemon. CSP_AND_CERTNAME 22.11.2017 17:42:55 Fehlersuche VPN AuthDaemon:Certificate was not loaded. 22.11.2017 17:42:55 Fehlersuche VPN authentication finished 22.11.2017 17:42:55 Fehlersuche VPN pki_get_mycert() return mycert null !!!! 22.11.2017 17:42:55 Information VPN ike_cfg_gw_init failed check the vpn gateway configuraiton
If I edit the xml and add <prompt_certificate>1 and choose the user cert the vpn connects also.
So it seems like the deployed vpn is not able to auto-select the right certificate.
"use windows store certificates" and "current user windows store certicates" ist enabled.
Any ideas?
Boris