FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
VinayHM
Staff
Staff
Article Id 278140
Description This article describes how to process when a user is not able to connect to an SSL VPN, the download stops at 40% (Azure SAML and  VPNSSL).
Scope FortiGate.
Solution

These logs show more information to explain why the user from AD is not able to connect:

 

__samld_sp_login_resp [842]: Failed to process response message. ret=-111(Failed to verify signature.)
samld_send_common_reply [114]: Code: 1, id: 576, data_len: 56
samld_send_common_reply [122]: Attr: 21, 8,
samld_send_common_reply [122]: Attr: 22, 32, Failed to verify signature.

 

The above error, generally indicates that this is the issue with the certificate used in SAML communication.

 

Try to import the correct certificate or reimport the certificate following this KB article: Technical Tip: Login issues with SAML IdP. 'Failed to verify signature' error in SAML Debug

 

Related KB article to troubleshoot SAML and SSL VPN:

Troubleshooting Tip: How to troubleshoot SAML authentication