Description
This article provides the solution when the error 'The server you want to connect to requests identification. choose a certificate and try again (-5)' is received in FortiClient trying to connect to the SSL VPN.
Scope
FortiGate.
Solution
This error can occur for the following reasons:
Microsoft has released both standalone packages and cumulative updates to fix this issue:
Cumulative updates:
Standalone Updates:
The updates cannot be deployed via Windows Update.
Download from the Microsoft Update Catalog and install it manually or import it into WSUS and Microsoft Endpoint Configuration Manager.
In sniffer, a Fatal error 'TLSv1.2 Record Layer: Alert (Level: Fatal, Description: Decode Error)' is seen.
In debugging output the error is seen:
Spoke1 # di de disable
Spoke1 # di de reset
Spoke1 # di de app sslvpn -1
Debug messages will be on for 30 minutes.
Spoke1 # di de app fnbamd -1
Debug messages will be on for 30 minutes.
Spoke1 # di de enable
[278:root:a]allocSSLConn:310 sconn 0x33f7cc00 (0:root)
[278:root:a]SSL state:before SSL initialization (10.125.3.81)
[278:root:a]SSL state:before SSL initialization (10.125.3.81)
[278:root:a]no SNI received
[278:root:a]client cert requirement: yes
[278:root:a]SSL state:SSLv3/TLS read client hello (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write server hello (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write certificate (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write key exchange (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write certificate request (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write server done (10.125.3.81)
[278:root:a]SSL state:SSLv3/TLS write server done:(null)(10.125.3.81)
[278:root:a]SSL state:fatal decode error (10.125.3.81)
[278:root:a]SSL state:error:(null)(10.125.3.81)
[278:root:a]SSL_accept failed, 1:unexpected eof while reading
[278:root:a]Destroy sconn 0x33f7cc00, connSize=0. (root)
Related article:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.