Skip to main content
ssriswadpong
Staff & Editor
Staff & Editor
February 27, 2026

Technical Tip: Server certificate must be selected for FortiClient SSO Mobility Agent Service after upgrading FortiAuthenticator to 6.6.3 or later

  • February 27, 2026
  • 0 replies
  • 77 views
Description This article describes a change in FortiAuthenticator 6.6.3 and later where the new menu for selecting a server certificate will be available for the FortiClient SSO Mobility Agent Service.
Scope FortiAuthenticator.
Solution

The new option is available under Fortinet SSO -> Settings -> Methods -> FortiClient SSO Mobility Agent Service -> Server certificate.

 

By default, there are 2 certificates - Factory 1 and Factory 2 - which correspond to Fortinet_CA1_Factory and Fortinet_CA2_Factory under Certificate Management -> End entities -> Local Services.

 

Screenshot 2026-02-06 101312.png

 

Note: If the FortiAuthenticator unit was originally running a version where 'Fortinet_CA2_Factory' was unavailable, upgrading to version 6.6.3 or higher will result in the default server certificate remaining as 'Factory 1' only.