Troubleshooting Tip: Devices showing offline with ‘Unknown CA’ error after FortiGate software upgrade
| Description | This article outlines an issue where devices may appear offline and show an ‘Unknown CA’ error after upgrading FortiGate software. This occurs because the certificate fingerprint changes after the upgrade, causing FortiAIOps to no longer recognize the FortiGate certificate as trusted. |
| Scope | FortiOS, FortiAIOps and FortiManager. |
| Solution | To resolve the issue of devices appearing offline with an 'Unknown CA' error after upgrading FortiGate software, the following options are available:
The previously mentioned options are documented in Troubleshooting Tip: How to troubleshoot an Unknown CA error for a managed FortiGate in FortiAIOps.
While the first two options are suitable for environments with a small number of devices, they may not be practical for larger deployments. This article focuses on the recommended approach for scalable environments:
FortiAIOps and FortiGate certificate requirements: Communication between the FortiAIOps application and FortiGate devices is secured using SSL/TLS encryption. As a result, FortiAIOps can successfully discover and manage a FortiGate only when a valid certificate is installed on the device. To ensure successful discovery, the managed FortiGate IP address or FQDN configured in FortiAIOps must match the Subject Alternative Name (SAN) field in the FortiGate certificate. A mismatch will result in discovery failure.
If the SSL certificate fingerprint changes following an upgrade, or if the certificate is signed by an untrusted Certificate Authority (CA), the discovery process will fail and an 'Unknown CA' error will be displayed.
SAN configuration requirements:
Best practice recommendation: For large-scale environments, it is recommended to deploy a custom certificate (e.g., a wildcard certificate) across all FortiGate devices. This approach ensures certificate consistency and prevents issues related to certificate fingerprint changes following software upgrades.
Steps to use custom certificates:
After authorizing the firewalls with the custom certificate, the devices should appear online and be successfully discovered.
If there is an issue with the Subject Alternative Name (SAN) field in the FortiGate certificate, the devices will display a 'Certificate SAN mismatch' error in FortiAIOps and appear with an offline status.
Related articles:
|




