Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ashik_k
Visitor

Captive portal issue

Upload.jpgI am facing an issue with the captive portal after updating Google Chrome. I am attaching a screenshot for reference.

Help please for solving the issue.

Regards,
Ashik

7 REPLIES 7
AEK
SuperUser
SuperUser

Check if the certificate authority certificate you are signing with is installed on your browser.

Chrome > Settings > Security > Manage Certificates.

AEK
AEK
ashik_k

its already checked

ebilcari
Staff
Staff

As I know this page should use http since its function is just to check if the host has internet access. Check the browser if there is any settings or extension that force every site to use https.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ashik_k

After that browser update we facing the issue. To get internet access, the authentication page needs to load. But right now, the authentication page is not loading, and instead, this error is appearing

ebilcari

Yes, usually this page is used by chrome to detect the lack of internet access and redirect to the portal page URL (the process happens in background and is not visible by the end user). This is done through http but it seems that after the upgrade something has change on chrome configuration/behavior. Maybe check if this option is now enabled:

 
 

chrome.PNG

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
ashik_k

its disabled, but issue not resolved.

pminarik
Staff
Staff

Well.. the error is pretty self-explanatory. The browser doesn't trust the CA that issued the server-certificate being presented.

 

I know you wrote that "it's already checked", but with all due respect I'd trust the browser's claim over yours.

 

1, On that error screen, click the red triangle and check what cert chain is being presented, up to the CA.

2, Inspect those certificates in details.

3, Compare the CA shown against the CA you're expecting to be used by the FortiGate for captive portals (by default controlled by config user settings > set auth-ca-cert).

[ corrections always welcome ]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors