Technical Tip: System certificate used by DNS proxy is not referenced
Description | This article provides an explanation of the apparent inconsistency between GUI and CLI references. |
Scope | FortiGate. |
Solution | In Network -> DNS -> SSL certificate, when 'Use FortiGuard Servers' certificate is being selected, as described as 'Used by a DNS proxy as a DNS server so that the DNS proxy can provide service over TLS, as well as normal UDP/TCP'. That certificate is not being referenced as per the GUI, while it is being referenced in the CLI.
![]() As a next step, the certificate is being changed. On the GUI, the change looks as follows: ![]() The change is being tracked with the CLI debug: As per the GUI reference in System -> Certificates, this certificate is not being referenced: ![]() However, as per the CLI, this certificate is referenced: For this purpose, an internal investigation was launched. As per the explanation of the engineering team, this behavior is not a bug, but is as per design: the datasource path is certificate.local (GLOBAL) as system.dns is GLOBAL; vpn.certificate.local is per VDOM. When the VDOM mode is not enabled, the user cannot operate the GLOBAL certificate.local, therefore. vpn.certificate.local is mirrored to certificate.local and therefore not referenced. |



