Created on
‎01-17-2024
07:06 AM
Edited on
‎02-26-2024
03:34 AM
By
Kate_M
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiSwitch: Forbidden....Reason: Cannot perform Post-Handshake Authentication.
This Tech-Tip desribes how FortiSwitch OS up till 7.4.0, can have issues with TLS 1.3.
- This is still an issue with 7.4.2!
- How come, this is a problem with latest browser versions, like Chrome & Firefox?
Are FortiSwitches telling it supports TLS 1.3, but in reality, it dosen't?
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
Solved! Go to Solution.
- Labels:
-
FortiSwitch
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As of now, we have no plan to change anything on switch side as it's a browser side issue. Safari is working fine. For Firefox, it is possible to fix it in 'about:config', and set 'security.tls.enable_post_handshake_auth' to 'true'.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Note: This does not seem to be an issue on Mac OS X's Safari..
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Jakob-AHHG,
The article you provided is for FortiSwitch OS 7.4.0 or above which includes 7.4.2. Did you follow suggestions provided in the article?
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ahh, my bad!
Yeah, just did that on a switch.. but why would I like to not use TLS1.3 ?!?
If I had old browser, I could understand..
Please fix! I do not want to have to apply this security downgrade to 100 switches!
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As of now, we have no plan to change anything on switch side as it's a browser side issue. Safari is working fine. For Firefox, it is possible to fix it in 'about:config', and set 'security.tls.enable_post_handshake_auth' to 'true'.
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Well, if it ain't your bug to fix, than I'm happy with that - then we just need pressure on the browser developers.. ;)
IT System Admin,
Arp-Hansen Hotrel Group A/S, Copenhagen, DK
