Hi Everyone,
I am running Fortigate 800c 5.2.2
The problem i am facing is as follows.
I have a identity based policy , which of course forces non domain machines (macs ) to authenticate to have the internet. Windows machines are fine as i have fsso in place and it works fine.
the problem i have is when a mac comes to authenticate again after the timeout period if it is using safari a authentication box appears , they in turn authenticate and continue on. However if they are using chrome on the MAC they just get a certificate error and cant continue. the work around is to open safari authenticate and then chrome is fine.
I also notice that in the logs i see it is being blocked
so i guess to cut a long story short chrome is not prompting to authenticate thus i am getting blocked , which in turn gives me the certificate error, and as i am using certificate based inspection, which if a page is blocked a certificate mismatch error occurs and if you procced you get the blocked page.
I get this too on chrome on a pc when you click proceed. Chrome gives you the Your connection is not private message. Authenticating with IE works fine.
FGT default use "self-sign" certificate for authentication, so some browser is not happy with it.
You may change it either way and did not use "self-sign" certificate
1.CLI:config sys global/set auth-cert xxx/end
or
2.CLI: config use setting /set auth-cert xxx/end
Thanks for the info.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.