Description | This article describes how to resolve a scenario where FortiManager HA is not syncing or forming when using custom certificates with SAN values configured. |
Scope | v6.4.0, 7.0.0, 7.2.0, 7.4.0 and above. |
Solution |
When running HA debug, the following errors can be seen printed:
2024-06-17 16:47:51 free connection to 172.27.x.x
When both CN and SAN are configured in a custom certificate, HA requires SAN to be the serial of the relevant FortiManager as it is used for verification of identity instead of CN. Existing SAN values do not need to be removed. The requirement is just for serial to be added as part of the values.
Once the serial of the Fortimanager has been added to the SAN values, HA should come up. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.