Resolved issues
The resolved issues listed below may not list every bug that has been corrected with this release. For inquiries about a particular bug, please contact Technical Support within the FortiCare portal.
Bug ID |
Description |
---|---|
505547 |
SSOMA configuration: Misleading error message. |
558390 |
Support TLS 1.3 in RADIUS EAP-TLS. |
599496 |
Support TLS 1.3 in |
741495 |
Error when trying to import users from FortiGate configuration to FortiAuthenticator v6.4. |
755752 |
Power supplies show voltage input fault on both CLI and GUI. |
756414 |
Incorrect Italian translation of the Next button displayed on the reset password page. |
766453 |
[FortiAuthenticator 400E] help check the reason of FortiAuthenticator 400E auto rebooting. |
781832 |
Token bypass not working for FIDO enabled self-service portal. |
825665 |
Wrong client IPv4 attribute for Fortinet SSO Methods > SSO > RADIUS Accounting Sources. |
842886 |
Upgrading FortiAuthenticator in HA-LB removed the MAC-address records form the LB node. |
853068 |
In the session expired token page entering wrong token does not redirect to Login page. |
868810 |
Heavy FSSO-linked DNS traffic could result in the loss of HA heartbeats. |
869867 |
FortiAuthenticator SSO database is not updating on time when domain users switch from wireless to wired or vice-versa. |
874450 |
Realm authentication performance regression with KVM FortiAuthenticator. |
876009 |
FortiAuthenticator ignores the groups filtering rules and send all SSO groups to FortiGate if FortiGate is configured with FQDN. |
877432 |
Selecting the cloud option for group membership on SAML SP displays 500 error if we do not select an OAuth server. |
887081 |
SAML: Launching SP-initiated SAML session for a user with FIDO AUTH produces server errors. |
887135 |
Admin password recheck popup should have a cancel button. |
887487 |
Request FortiAuthenticator with CA only to support future new FortiGate with CA2 only. |
890725 |
SAML token-only login displays password page instead of the token page. |
894888 |
User lookup does not display token information with view-only admin profiles. |
897852 |
Add warnings, logs, and SNMP traps on LB HA failures. |
900664 |
Certificate only smart connect in iOS does not work. |
903714 |
TACACS+ remote users are not being displayed in User Lookup. |
903747 |
Instruction link for installing FortiToken Mobile application is blocked on the self-service portal. |
904647 |
HA status table header giving JavaScript errors when we clicked on. |
905423 |
CRL download URL over http is not available. |
906150 |
Improve performance in SAML login GET request. |
906634 |
We can access SAML IdP initiated URL on a FortiAuthenticator using a server address that is not the FQDN or IP. |
908091 |
When |
908291 |
FortiAuthenticator does not properly revoke a user certificate. |
908753 |
Number of Users for the MAC device group is always zero. |
908759 |
HA LB anomaly for the MAC device group membership upon connection. |
909099 |
Refresh button for widgets gets grayed out for a while after clicking on it. |
909342 |
Import hard token through the serial number file, status |
910331 |
Next button to trigger FIDO authentication should be disabled when FIDO authentication is in progress. |
911300 |
The self-service portal password change error is displayed in two places. |
911347 |
Proper fix |
911389 |
Remove Certificate authority type and CA certificate that issued the server certificate from Web/LDAP server configuration page. |
913354 |
Self-device enrollment is broken for FortiToken 300. |
913981 |
Non-admin SAML FIDO authentication ends with error 500. |
914755 |
FortiAuthenticator is not sending the userip to the Syslog server when using RADIUS authentication. |
917189 |
Add more built-in tiles for SAML IdP-initiated portal. |
920262 |
Some of the users logged in MAC devices are unable to get user sessions listed on FortiAuthenticator. |
920702 |
Requiring a password recheck should be necessary when adding a FIDO key to the Admin user. |
921147 |
Oauth relying parties should have unique name constraints. |
921851 |
Unable to scroll User Registration Replacement Messages page. |
921949 |
We should not be able to save Smart connect profiles if EAP type has not been selected. |
922974 |
406 error when prompted for the Admin password. |
923697 |
RADIUS policies matching attributes configuration should not be limited to two. |
924446 |
500 error for a remote user on the SAML portal with both FIDO and FortiToken Mobile/FortiToken Cloud token. |
924632 |
FortiAuthenticator unable to return more than 100 groups from the Azure AD when using SSOMA. |
924867 |
GUI crashes when creating a usage profile. |
925402 |
FortiAuthenticator base distinguished name- Click on the browser displayed error code if OU has special characters in the name, e.g., |
926385 |
FortiToken sync issue after upgrading from a previous GA build. |
927104 |
The User Lookup feature displays only the most recent session for active RADIUS sessions. |
927117 |
When attempting to revoke a server certificate, the Certificates field is empty. |
928034 |
Issue authenticating IPsecVPN IKEv2 EAP (MSCHAPv2) to FortiAuthenticator + remote RADIUS server. |
928334 |
Incorrect message on landing page for |
928643 |
|
928803 |
Syslog over TLS enabled offers TLS 1.0 and TLS 1.1 on port 6514. |
929004 |
Unable to add longer mobile phone numbers for certain country codes. |
929090 |
FortiAuthenticator issues with |
929279 |
Self-service portal password change fails for remote LDAP users. |
929380 |
Typo: Fix typo when deleting FortiToken mobile. |
929726 |
HA cluster fails to provision FortiToken Mobile tokens on the primary after a failover. |
929943 |
Push authentication does not work on the Windows Agent when using FortiTrust Identity. |
931034 |
Coordinated upgrade from build 0073 (6.0.8) GA to 1349 results in errors in the HA cluster mode. |
931246 |
CRL automatic download failed using https. |
931960 |
|
932783 |
FAC2KE PSU monitor widget does not accurately reflect the actual statuses of the PSUs on the device. |
933747 |
REST API - |
934078 |
FortiAuthenticator allows and forwards TS-Agent and DC-Agent login for the same IP address. |
934489 |
SmartConnect profile user certificate not containing the correct UPN. |
934535 |
500 error when re-enabling a disabled local user with Account Expiration enabled. |
934567 |
Internal Server Error (Disk full) on the users certificate GUI with 50K+ certificates. |
934573 |
Language changes in LEGACY self-service portal when an admin is connected affect admin GUI language. |
934872 |
Auto-redirect to the trusted endpoint SSO URL. |
935590 |
REST API does not return company and department fields for local users. |
937201 |
Sync rule with any OTP method including None generates excessive logs. |
937917 |
Custom user fields in user portal settings gives 403 error when editing it. |
939073 |
|
939829 |
If a user logs in to FortiAuthenticator first, then logs in to the OAuth application, the user will be logged in with the FortiAuthenticator login session. |
939909 |
|
940443 |
FortiAuthenticator - FortiOS/FortiProxy - Proxy mode with deep inspection - Stack buffer overflow. |
941685 |
Create new log events for RADIUS accounting start/stop messages. |
941695 |
Adding TACACS+ clients from a csv file allows to enter an incorrect IP address format |
942419 |
Syslog FSSO - Parse for multiple IPv4 and IPv6 addresses. |
943843 |
FortiAuthenticator HSTS settings are not applied to the |
944392 |
Post request will cause CSRF validation error if the URL contains port number other than 80 or 443. |
946677 |
Eliminate |
947031 |
SAML SP FIDO OTP fallback using Azure IdP proxy with an imported remote SAML Azure with token fails. |
948072 |
Improper requests to |
948184 |
Upgrade to 6.5.3 fails and leaves FortiAuthenticator unusable. |
948606 |
LDAP group filter query fails when 3 CN is chosen. |
949269 |
Remote LDAP user should be denied in RADIUS if user has not been imported. |
950252 |
CSV Mac device import fails due to MAC address wildcard formatting. Previously, resolved in 0665381. |
950260 |
Change in FortiToken Cloud 'balance' API broke inventory widget. |
950326 |
FortiAuthenticator keep sending non-stop traffic to |
950696 |
OAuth portal is optional. |
950709 |
Creating users using the |
951049 |
FortiToken hardware token is not assigned to the imported users if None is not selected in the sync rule. |
951966 |
GUI not showing groups when trying to import user by group membership attribute from the OpenLDAP server. |
952537 |
Certificate renewal failure after revocation. |
953096 |
Close all of the FortiAuthenticator service ports by default. |
953106 |
Unable to change Fortinet logo on one of the replacement messages. |
954178 |
Avoid sharing the database session across different HTTP requests. |
954681 |
Test token with email/SMS not working due to CSP error. |
955548 |
Internal error 500 when trying to visualize the remote TACAC+ users. |
957153 |
Dynamic RADIUS attribute feature should work for an AD user. |
957281 |
|
958112 |
Using special character in the Service Provider settings breaks SAML with 403 error. |
958660 |
Windows AD SSO domains randomly disconnected from FortiAuthenticator(when polling dozens). |
960241 |
Unable to redirect to a page after successful kerberos authentication - |
960694 |
Trusted CA deletion does not generate a log message. |
961100 |
Restoring encrypted configuration with wrong password gives |
962037 |
Issues when moving users from column Available Users to Chosen Users. |
962222 |
wad |
962359 |
Allow changing access rights in the FortiAuthenticator Cloud mode. |
963519 |
Translation error in OAuth Service > General > JWT private key. |
964676 |
It takes around 10 seconds to create or migrate IAM user on any account. |
964839 |
Do not display firmware certificates as options for CA certificate when FortiAuthenticator is in HA LB mode. |
965871 |
SAML stops working with error 500 due to captcha errors. |
966223 |
Internal server error 500 when viewing RADIUS Accounting Sessions in Monitor section. |
966225 |
Unable to create multiple realms with the same remote SAML server. |
967020 |
500 Internal server error on SAML when authenticating with SAML with captcha enabled. |
967065 |
Admin login with FortiToken Mobile/Cloud push failure with an empty field. |
967789 |
Windows agent authentication using FortiToken Cloud with Email and SMS delivery option fails. |
968656 |
Unable to configure the fourth and the last realm in Authentication > SAML IdP > General. |
970809 |
SAML trusted endpoint FSSO return internal error 500. |
971069 |
wad/ |
973586 |
Fido OAuth authentication flow is broken. |
973754 |
Incorrect password with PCI mode enabled results in 500 error. |
977602 |
Enable HSTS by default. |
925924 |
Unable to get SSO session on FortiAuthenticator when using UPN to log in. |
876897 |
FortiAuthenticator memory usage showing in the widget does not match with memory usage from SNMP ( |
936356 |
|