FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
SAJUDIYA
Staff
Staff
Article Id 271863
Description This article describes that the error 'Denied: cert auth failed, cert-status:untrusted fail-reason:(null)' occurs due to the certificate is not authorized or a bad certificate installed in FortiGate. ZTNA rules and servers are also configured correctly.
Scope FortiGate.
Solution

To identify the issue with the certificate:

 

  1. Run WAD debug to see the output below:

diag wad debug enable category all
diag wad debug enable level verbose
diag wad filter src 138.x.x.x <----- Source IP of endpoint public IP.

diag wad filter dport 19443   <----- Destination port.

diag debug enable

 

User-Agent: Forticlient
Accept: */*
Cookie:
Authorization: Basic

 [p:246][s:127994288][r:17225144] __wad_http_build_replmsg_resp :632 Generating replacement message. Invalid ZTNA client certificate, reason: certificate signature failure repmsg_id 70

 

  1. Check forward traffic logs:

"
date=2023-05-18 time=22:28:44 id=xxxxx itime="2023-05-18 23:28:45" euid=3 epid=101 dsteuid=3 dstepid=101 logflag=3 logver=702041396 type="traffic" subtype="ztna" level="notice" action="deny" policyid=1 sessionid=153278634 srcip=173.2.47.250 dstip=192.226.87.5 srcport=49756 dstport=8443 duration=0 proto=6 sentbyte=1711 rcvdbyte=0 logid=0005000024 srcname="xxx.xxx.net" dstname="192.x.x.x" service="Filezilla ports" app="Filezilla ports" appcat="unscanned" srcintfrole="wan" dstintfrole="undefined" policytype="proxy-policy" eventtime=xxxxx wanin=0 wanout=0 lanin=1711 lanout=1593 crscore=30 craction=131072 crlevel="high" poluuid="xxx" srccountry="United States" dstcountry="United States" srcintf="wan1" dstintf="root" policyname="VendorZTNA-Rule" msg="Denied: cert auth failed, cert-cn:E1BEA29xxx, cert-issuer:FCTEMSxx, cert-status:untrusted fail-reason:(null)" threatwgts=30 threatcnts=1 threatlvls=3 threats=blocked-connection threattyps=blocked-connection tz="-0400" vip="fortigate_access" accessproxy="fortigate_access" devid="FG101Fxxx" vd="root" dtime="2023-05-18 22:28:44" itime_t=1684466925 devname="CT-Fortigate"

 

Solution:

  • From FortiGate, go to Security Fabric -> Fabric connectors, and edit Forticlient EMS.
  1.  Delete and authorize the again Security Fabric.
  2. Go to Forticlient EMS and authorize the new Fabric Connector in EMS and it should work.
Contributors