FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
yangw
Staff
Staff
Article Id 361713
Description This article describes how to investigate the token keeps status pending activation issue on FortiAuthenticator.
Scope FortiAuthenticator 6.6.0 and below.
Solution

Verifying the true cause:

 

FortiAuthenticator unit with version 6.6.0 and below encountered the status of the FortiToken mobile keeps Pending.

 

The access log below can be used to check the token status to identify if the issue is related to bug ID: 988000.

 

Trigger Condition: Reboot FortiAuthenticator when FTM servers are unreachable.

 

See Resolved issues 6.6.1.

 

To download the FortiAuthenticator debug reports in GUI -> Logging -> Log Access -> Log and there, select the Download dropdown and download:

 

logovi.PNG

 

One of the system event logs:

 

date=2024-01-08 time=14:30:14+0000 oid=1427862 logid=30909 cat="Event" subcat="System" level="warning" nas="" action="" status="" msg="FTM deprovision: disabled remote LDAP user 'muriiel.laavy' because FTM activation has expired. Admin must be cautious to re-enable this user because it will be allowed access without token." user="admin"

 

Action plan:

 

If the system event log matches, it would match the bug ID, arrange an available time to upgrade firmware to 6.4.10, 6.5.5 or 6.6.1 to fix the issue.