FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
VinayHM
Staff
Staff
Article Id 278140
Description This article describes how to process when a user is not able to connect to an SSL VPN, the download stops at 40% (Azure SAML and  VPNSSL).
Scope FortiGate.
Solution

These logs show more information to explain why the user from AD is not able to connect:

 

__samld_sp_login_resp [842]: Failed to process response message. ret=-111(Failed to verify signature.)
samld_send_common_reply [114]: Code: 1, id: 576, data_len: 56
samld_send_common_reply [122]: Attr: 21, 8,
samld_send_common_reply [122]: Attr: 22, 32, Failed to verify signature.

 

The above error, generally indicates that this is the issue with the certificate used in SAML communication.

 

 

Related KB article to troubleshoot SAML and SSL VPN:

Troubleshooting Tip: How to troubleshoot SAML authentication

Contributors