Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
momon
New Contributor

Problem with user certificate

Hello I am using a fortigate VPN. I post pages in the user's panel, via VPN-Portals. The problem is that one of the pages requires a user certificate and when the user wants to enter the site, the message "no certificate" appears. The user has this certificate imported into the browser and when he does not use VPN, the website works properly. The problem arises when I log into the VPN and want to use the bookmark. The certificate has the .p12 extension. Each user of this website has their own certificate. How can I fix the problem for the website to work via VPN? Should I import the certificate somewhere or somehow force the VPN to read certificates from the browser? Thank you for your help.

4 REPLIES 4
boneyard
Valued Contributor

haven't tried this exact scenario with fortigate sslvpn webportal but knowing how client certificates work this isn't possible.

 

there has to be an end to end ssl sesion between the client and the server. if you put something like a reverse proxy or sslvpn webportal in between the client certificate will be available there at the front but not behind it.

 

client ssl certificates are used to proof who you are, so with a sslvpn before the website i would say the client certificate wouldnt be needed, but that is something for the customer to decide.

Yurisk

Have you considered switching to the Tunnel from Web mode?

 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
momon
New Contributor

No, could you say more?

sw2090
SuperUser
SuperUser

That sounds like if you route all traffic through the vpn once it is up and running and your Gateway does some proxying. If it is a FGT it might have some UTM like deep or certificate inspection enabled on the matched policy.

 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors