Skip to main content
kwcheng__FTNT
Staff
Staff
October 2, 2024

Technical Tip: Deleting the default local certificate of the FortiGate

  • October 2, 2024
  • 0 replies
  • 1508 views
Description This article describes that deleting the default local certificate of the FortiGate is not possible.
Scope All FortiOS platform
Solution

All FortiOS comes with its respective default self-signed local certificates. These default certificates are as follows:

 

Fortinet_CA_SSL
Fortinet_CA_Untrusted
Fortinet_Factory
Fortinet_Factory_Backup
Fortinet_GUI_Server
Fortinet_SSL
Fortinet_SSL_DSA1024
Fortinet_SSL_DSA2048
Fortinet_SSL_ECDSA256
Fortinet_SSL_ECDSA384
Fortinet_SSL_ECDSA521
Fortinet_SSL_ED448
Fortinet_SSL_ED25519
Fortinet_SSL_RSA1024
Fortinet_SSL_RSA2048
Fortinet_SSL_RSA4096
Fortinet_Wifi

 

These default certificates cannot be deleted or removed even if it is not being used. The following error will prompt if the administrator tries to delete them via CLI:

 

Tiara-kvm05 (local) # delete Fortinet_Wifi
Can not delete a static table entry
Command fail. Return code -61

 

This is an expected behavior and should not be a concern. Just replacing the certificate under its respective configuration with the new imported local certificate is sufficient if replacing the default self-signed local certificate is required.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!