Skip to main content
btan
Staff & Editor
Staff & Editor
May 11, 2026

Technical Tip: FortiClient EMS cannot generate a digitally self-signed FortiClient exe installer

  • May 11, 2026
  • 0 replies
  • 172 views

Description

This article describes why FortiClient EMS cannot generate a digitally self-signed FortiClient exe installer.

Scope

 FortiClient EMS v7.4 onwards

Solution

When the end user manually runs a FortiClient exe installer in an attempt to upgrade FortiClient version, Windows Microsoft Defender SmartScreen will pop-up below message:

d75f0ed6.png


The user will have to select 'Run anyway ' to upgrade FortiClient.

Below is the reason why FortiClient EMS can never self-sign a FortiClient exe installer:

Private key security risk.
The signing certificate private key must be stored on the FortiClient EMS server. In the event where the server itself is compromised, the bad actor will be able to obtain the software's private key and use it to sign their malware as 'trusted and made by Fortinet'.


To avoid this pop-up message from appearing, it is possible to upload the company's own digital certificate to sign the FortiClient EMS-packaged FortiClient exe installer.

  1. Go to System Settings -> EMS Settings -> Sign Software Packages -> toggle ON.

  2. Input the timestamp server FQDN or IP, upload the Certificate -> Save.

  3. For the existing FortiClient installer, edit the installer in any way to repackage it. The repackaged installer will be signed by the certificate uploaded in step 3.

  4. When creating a new FortiClient installer, it will be signed by the certificate, too.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!