Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Magdalena
New Contributor III

FortiClient shows "failed to verify server certificate" message

I am using FortiClient Version 7.2.7 and whenever clients try to connect to the EMS withing the LAN they receive a "failed to verity server certificate" message.

Connecting via a mobile hotspot works.

Does anyone know why this is happening and how i can fix it?

 

4 REPLIES 4
AEK
SuperUser
SuperUser

Are you connecting with hostname or IP address?

Bear in mind that if the used hostname or IP is not the same as the certificate subject or SAN then you will receive certificate error.

AEK
AEK
Magdalena
New Contributor III

I am connecting to the host name

The name is the same as in the certificate

AEK

This should mean that you don't see the same certificate on WAN (mobile hotspot) and on LAN, which is not supposed to be so.

Try run this command from both WAN and LAN to confirm that the certificate is (or is not) the same.

openssl s_client -connect YourServerIP:8013

 

AEK
AEK
MZBZ
Staff
Staff

Starting from FortiClient 7.2.5+, renewing the SSL cert on FortiGate will trigger a security feature on FortiClient. This is known and will change in the next version. You can contact TAC for the issue id.

 

Solution is to disconnect FCT from EMS and shutdown FCT (right click tray area and shutdown). Then delete FortiClient folder in %appdata% and %localappdata% and reboot the system.

 

M. B.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors