Our VPN SSO has stopped working. I attempted the following steps without success:
Enabled the signed response option in Google
Disabled and re-enabled it
Downloaded a new certificate from Google and uploaded it to the FortiGate
Despite these changes, SSO is still failing. The FortiGate logs show the following error:
From what I understand, this may be a known issue. Is there a fix or recommended workaround available?
downgrade to 7.2.11 it is then.
Hi, the original recommendation for Google IdP was mistaken.
Neither Signed response enabled nor disabled fulfill the current FortiOS requirements (needing both Reply and Assertion(s) signed), so this is currently unresolvable in 7.4.9. You will need to downgrade to a previous firmware version for the time being. The requirements will be loosened in the next firmware release to ensure compatibility with Google IdP or other potential IdPs that cannot be configured to provide signature in both elements.
User | Count |
---|---|
2642 | |
1405 | |
810 | |
685 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.