Hello,
I am having an issue finding and then matching the "subject" of the user certificate for the users I created in this walk-through. From the directions, I get the feeling they expect you to know this, which I don't. Hopefully this makes sense and someone can help me out.
Currently, I am unable to connect to my VPN and feel this might be the issue.
Thank you for your help!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Try to enable debug CLI: dia debug app fnbam -1, it will show up PKI user/Certificate match.
FGT will check certificate send from browser with PKI user match, in this case, "Set subject User01". The certificate import to your browser (IE/Firefox) should have Subject like "C = US, ST = California, L = Sunnyvale, O = Fortinet, OU = FortiGate, CN = User01, emailAddress = support@fortinet.com".
Thanks.
add CLI: dia debug enable, if you want see debug on "CLI console". You may use small box without Console. Thanks.
I know this in an older post but I thought it'd be good trying to provide further clarification. As mentioned by Jeff, you are able to see the contents of the certificate you're using by opening it in a Windows machine for example.
Open your certificate, go to the tab "Details" and look for the field "Subject". What you're looking for - and what should match in your FortiGate's configuration - is whatever is after "CN" or CommonName, and only that.
In my case, the subject field for my PKI user is "vinisantos".
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.