I am implementing certificate-based authentication for Windows logon using FortiToken 310 and FortiAuthenticator.
Configuration steps completed:
Integrated FortiAuthenticator with Active Directory.
Created a Root CA on FortiAuthenticator.
Generated a user certificate, signed it with the FAC CA, and imported it into the FortiToken 310 via FortiToken Manager.
Configured the token PIN.
Imported the FAC Root CA into the Windows Trusted Root Certification Authorities store on the test PC.
Enabled smart card logon policy on the Windows test machine.
Test results:
The Windows login screen recognizes the FortiToken smart card.
The PIN is accepted successfully.
However, authentication fails with the error:
"The credentials could not be verified."
FortiAuthenticator FortiToken 310 #Windows logon
@Anonymous
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello @ilyas1
It seems an issue on the Windows side to be able to check the certificat included on your smartcard.
Please check the Microsoft KB and the Certificat Store used :
Hello,
Thank you for your reply.
Please find below the FortiAuthenticator logs after enabling debug mode and reproducing the test.
Mon Aug 18 16:13:30 2025 user authentication error: user not partially authenticated
ID 1345
Timestamp Mon Aug 18 16:13:30 2025
Level information
Action Authentication
Status Authentication
Source IP FAC_GUI
Message user authentication error: user not partially authenticated
User admin
Log Type
Type Id 20328
Name Authentication Failed No Partial Auth
Sub Category Authentication
Category Event
Description Authentication failed, user has not been partially authenticated
Hello @ilyas1
Can you check with the FAC Debug view directly ?
https://<FAC IP>/debug/
You can check in the RADIUS /LDAP sections
Here is a KB to be able to check :
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.