Technical Tip: Explanation on Fortinet_Factory certificate
| Description | This article describes more information on hardware-unique certificates: Fortinet_Factory and Fortinet_Factory_Backup. |
| Scope | FortiGate. |
| Solution | The 'Fortinet_Factory' and 'Fortinet_Factory_Backup' certificates are unique to each device.
They are generated when the unit is produced and cannot be regenerated. Their private key does not appear in the configuration file.
Correction: a previous version of this article stated the 'Fortinet_Wifi' certificate is also unique to each device. This is not correct- Fortinet_Wifi is a publicly signed certificate included in the certificate bundle and is the same for all units that have the same version of the certificate database. See this article: Technical Tip: Fortinet_Wifi certificate expiration.
Fortinet_Wifi, Fortinet_Factory, and Fortinet_Factory_Backup do not exist in the backup configuration. The certificates are not transferable from one unit to another by restoring the backup config.
Note: In a HA environment, the secondary unit will sync these certificates with the Serial Number from the Primary unit.
Devices with Fortinet_Factory certificates in TPM: Starting in FortiGate 200G/201G, some platforms have the Fortinet_Factory and Fortinet_Factory_Backup private keys stored on the device's Trusted Platform Module (TPM) and restrict the use of these certificates to hardcoded system functions only. See the document FortiGate identity stored in TMP for more information.
Devices with this enhancement do not support an administrator applying Fortinet_Factory for services requiring an SSL certificate. A new certificate, 'Fortinet_Default_SSL' is provided for this purpose, although it is still recommended to use a publicly or privately signed certificate where identity verification is required. |

