Question
FortiGate-90G Fabric Connector failing to verify FortiClient EMS public certificate (Error Code -9999)
Hi Fortinet Team,
Â
FortiClient EMS certificate not authorized..
I am experiencing an issue connecting my FortiGate-90G to an On-Premise FortiClient EMS server via the Fabric Connector. The connection fails with certificate verification errors.
Environment Details:
- FortiGate Model: FG-90G
- FortiGate and EMS Location: Both devices are in the same local subnet (192.168.2.x).
- DNS Setup: Configured via a Local DNS Database entry on the FortiGate, pointing the FQDN to the local EMS IP. Pings to the domain name resolve correctly.
- EMS Certificate: A valid Public Domain Certificate issued by RapidSSL / DigiCert (Domain: winxsfp.com).
Symptoms & Errors Observed:
- The Fabric Connector GUI shows an "Untrusted Certificate" status.
- I have disabled strict common name checking using the
set trust-ca-cn disablecommand underconfig endpoint-control fctems, but the issue persists. - Running the verification command in the CLI results in the following error output:
text
FortiGate-90G # execute fctems verify 1
Error in requesting EMS fabric connection: -4
issue in getting capabilities. EMS server certificate is not signed by any known CA.
Error (-1@_get_capabilities:513).
Command fail. Return code -9999Use code with caution.
- Attempting to upload the RapidSSL Intermediate CA certificate via the GUI panel results in an "Incorrect certificate file format" error, and manual CLI string additions fail validation
