Fortinet 7.2.12 and 7.6.4 Azure SAML signing issue

In the release notes of 7.2.12 and 7.6.4 you will see something like this:

After upgrading you will not be able to connect to the IDP until you fix this. This blog entry will show how to modify the signing options in Azure which will resolve the issue.

Once the firewall was upgraded, SAML auth was failing to Azure on the SSL VPN. I debugged out the authentication attempts (dia deb app samld -1) and saw the following: Signature element not found.

To fix this we have to go into Entra Apps, and the SSL VPN app we are using and modify the SAML signing option.

Check these two screenshots on how. First go to your app as mentioned above, and then the “Single Sign-on” section. Next click on the edit under the SAML cert selection.

Next lets change the setting for signing:

After changing these settings I was able to connect just fine. So whats actually happening here?

SAML signing involves using a digital certificate by an Identity Provider (IdP – Azure) to create a digital signature for a SAML Response or Assertion, which is then used by a Service Provider (SP or – Fortigate) to verify the data’s integrity and origin. A SAML Assertion contains user identity and authorization details, while the Response is the XML envelope that carries these assertions and other information from the IdP to the SP to facilitate Single Sign-On (SSO). Signing the entire Response ensures the whole message, including its assertions, is trustworthy and hasn’t been altered. So basically its a way to increase security by making sure that both parts are signed by the trusted IDP cert.

7 responses to “Fortinet 7.2.12 and 7.6.4 Azure SAML signing issue

  1. ERK September 25, 2025 at 7:38 am

    Thank you! You saved my day!

  2. Vincent Homans September 29, 2025 at 4:55 am

    Thank you!!!
    Our automatic update during the night from Saturday to Sunday caused SSL VPN authentication to stop working. This post saved me some extra work debugging and downtime this weekend. I really appreciate you sharing this fix!

  3. broszkiet September 30, 2025 at 3:02 am

    Thanks for this post.
    Saved a lot of time.

  4. Matt September 30, 2025 at 3:36 pm

    Thank you!!!!!

  5. Nekdo October 2, 2025 at 10:25 am

    Thanx from Prague CZ, it works fine!

  6. Klaus Doll October 3, 2025 at 4:09 am

    Thanks a lot!!

  7. Di December 4, 2025 at 4:55 pm

    Thank you for sharing!!

Leave a Reply to Vincent HomansCancel reply

Discover more from TravelingPacket - A blog of network musings

Subscribe now to keep reading and get access to the full archive.

Continue reading