Created on
10-08-2024
06:09 AM
Edited on
10-08-2024
07:57 AM
By
Jean-Philippe_P
Description |
This article explains how to resolve common invalid certificate errors encountered during SSL VPN user authentication using SAML.
Error: 'NET:ERR_CERT_COMMON_NAME_INVALID'.
|
Scope | FortiGate. |
Solution |
When using the SAML authentication for SSL VPN, the redirected URL is an IP address instead of a domain name. The browser checks the certificate and finds that it was issued to the xxx.xxx.org domain instead of the IP address. This mismatch causes the 'NET:ERR_CERT_COMMON_NAME_INVALID' error.
There are 2 ways to resolve it.
Note: After replacing the IP address with the domain name, update the IdP configuration by replacing the SP-provided URL with the domain name in place of the IP address and ensuring that the URLs are similar on SP and IdP. |