Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CaryWells
New Contributor

VPN SSO not working – signature verification errors

 

Our VPN SSO has stopped working. I attempted the following steps without success:

  • Enabled the signed response option in Google

  • Disabled and re-enabled it

  • Downloaded a new certificate from Google and uploaded it to the FortiGate

Despite these changes, SSO is still failing. The FortiGate logs show the following error:

 

"__samld_sp_login_resp [828]: Failed to process response message. ret=101(Signature element not found.)"
 

From what I understand, this may be a known issue. Is there a fix or recommended workaround available?

11 REPLIES 11
funkylicious

downgrade to 7.2.11 it is then.

"jack of all trades, master of none"
"jack of all trades, master of none"
pminarik
Staff
Staff

Hi, the original recommendation for Google IdP was mistaken.

Neither Signed response enabled nor disabled fulfill the current FortiOS requirements (needing both Reply and Assertion(s) signed), so this is currently unresolvable in 7.4.9. You will need to downgrade to a previous firmware version for the time being. The requirements will be loosened in the next firmware release to ensure compatibility with Google IdP or other potential IdPs that cannot be configured to provide signature in both elements.

[ corrections always welcome ]
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors