Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
strongX509
New Contributor III

IPsec IKEv2: No CA certificate chain sent anymore after upgrade to FortiOS v7.4.3

The send-cert-chain attribute set to enable by default in the vpn ipsec phase1 configuration does not cause the CA certificate chain (unnecessary Root CA certificate plus Issuing SubCA certificate) to be included anymore in the IKE_AUTH response by the FortiGate 100F VPN gateway after upgrading to FortiOS v7.4.3. Before the upgrade everything was working fine. Is this an unintended regression introduced by the firmware upgrade?

3 REPLIES 3
strongX509
New Contributor III

We upgraded from FortiOS 7.4.1 so the send-cert-chain bug could already have been introduced with version 7.4.2.

strongX509
New Contributor III

No reaction at all from Fortinet on the apparent send-cert-chain bug?

smaruvala
Staff
Staff

Hi,

 

- Have you tried to take ike debug for the IPSEC negotiation along with the debug for fnbamd process as well? 

- I have not heard of a reported issue regarding this. Collecting the debugs will help us if we can see any issues with the negosiation.

 

Regards,

Shiva

Labels
Top Kudoed Authors