Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ndespres
New Contributor

Error "get_ha_sync_obj_sig_4dir" in new HA setup

Hi all, new to this world after a decade of supporting and managing Sonicwalls. Done a few smaller setups of Fortigate 60E's, but this is my first big one, setting up a new HA pair of 400E's in active/passive setup. I updated firmware on both devices to FortiOS v6.4.1 build1637 (GA) and am now repeatedly getting this error in the console of the master unit, whenever the secondary unit is online. The error does not appear in the console of the secondary unit.


get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2
get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/5c44d531.0 error 2
get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/157753a5.0 error 2

 

HA status in the GUI looks normal.

 

Can you please help me work through how to troubleshoot and resolve this issue? I'm struggling to find a command that lets me see what these certificates are, or what "error 2" is. I haven't loaded any of my own certificates yet.

 

Thanks in advance for your help!

4 REPLIES 4
Statista
New Contributor

same Problem here with ticket Number: 4105192

tried in different ways, always with the same result -.-

Statista

because nobody of the support team could really help me i have solved the problem "qiuck & dirty". Compare Backup of Master & slave FGT. Change the Master Backup to restore to slave FGT. the following must be changed: hostname ha device priority

MichaelA1
New Contributor

I was seeing them as well on multiple clusters.  I was just preparing to update one of the clusters to 6.4.2 and saw this in the console:

 

get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/5c44d531.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/157753a5.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/def36a68.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/c0ff1f52.0 error 2 get_ha_sync_obj_sig_4dir: stat /etc/cert/ca/988a38cb.0 error 2

but after the upgrade, I saw this on the console of the original master just after it came online after the reboot.

get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/988a38cb.0 --> /etc/cert/ca/root_NetLock_Arany_(Class_Gold)_Főtanúsítvány.cer get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/5c44d531.0 --> /etc/cert/ca/root_Staat_der_Nederlanden_Root_CA_-_G2.cer get_ha_sync_obj_sig_4dir delete broken symbolic link /etc/cert/ca/157753a5.0 --> /etc/cert/ca/root_AddTrust_External_Root.cer

 

I have been debugging/watching the console, no more errors.  Maybe they added a root cert cleanup?  I have not scrubbed the full release notes but...

kichitan
Staff
Staff

Bug was solved on version 6.4.2

 

https://docs.fortinet.com/document/fortigate/6.4.2/fortios-release-notes/289806/resolved-issues

 

Check under HA bus number 639307



Change is the only constant :)
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors