Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Bradford Networks\Persistent AgentThe 'homeServer' string holds the correct FQDN that is resolvable to the FortiNAC IP or it holds the IP of the FortiNAC directly.
Computer\HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Bradford Networks\Persistent Agent
2020-01-10 17:37:11 UTC :: SecureAgentTransportV1 constructor finishedThis issue is found when the Client does not trust the certificate that has been used to sign the 'Portal SSL' certificate configured on the FortiNAC GUI settings.
adding KeyExpiredListener
2020-01-10 17:37:11 UTC :: Server: fortinac.forti.lab, tcp: 4568, udp: 4567
2020-01-10 17:37:11 UTC :: Host = fortinac.forti.lab
2020-01-10 17:37:11 UTC :: SSL_get_verify_result = 0
2020-01-10 17:37:11 UTC :: SSL Certificate verification result: ok
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:22
Signature Algorithm: sha256WithRSAEncryption
Issuer: DC=lab, DC=forti, CN=fortilab
Validity
....
X509v3 CRL Distribution Points:
Full Name:
URI:ldap:///CN=fortilab,DC=forti,DC=lab?certificateRevocationList?base?objectClass=cRLDistributionPoint
Authority Information Access:
CA Issuers - URI:ldap:///CN=fortilab,DC=forti,DC=lab?cACertificate?base?objectClass=certificationAuthority
1.3.6.1.4.1.311.20.2:
...W.e.b.S.e.r.v.e.r
X509v3 Key Usage:
Digital Signature, Key Encipherment
X509v3 Extended Key Usage:
TLS Web Server Authentication
Signature Algorithm: sha256WithRSAEncryption
35:bc:bb:18:4f:0b:ef:e1:22:59:08:d2:aa:6d:92:fa:0c:e0:
6b:66:be:ef:b7:84:2a:64:be:9a:ca:fe:41:79:f2:18:3a:b4
2020-01-10 17:37:11 UTC :: peer CommonName = NAC-NEW
2020-01-10 17:37:11 UTC :: SAN: nac.forti.lab
2020-01-10 17:37:11 UTC :: Checking Peer name fortinac.forti.local against Common or Subject-alternative-name entry NAC-lab
2020-01-10 17:37:11 UTC :: Peer name "fortinac.forti.lab" doesn't match "NAC-lab"
2020-01-10 17:37:11 UTC :: Checking Peer name fortinac.forti.local against Common or Subject-alternative-name entry nac.forti.lab
2020-01-10 17:37:11 UTC :: Peer name "fortinac.forti.lab" doesn't match "nac.forti.lab"
2020-01-10 17:37:11 UTC :: Refusing to connect to trust_DISTRUSTED fortinac.forti.local|NAC-lab
2020-01-10 17:37:11 UTC :: Connection failed! 1
Related Articles
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.