Skip to main content
Kush_Patel
Staff
Staff
October 26, 2022

Troubleshooting Tip: Deleting a local certificate with no references that gives a 'Currently being used' error

  • October 26, 2022
  • 0 replies
  • 14152 views
Description

This article explains how to delete a local certificate despite receiving the error 'Can't delete this certificate. It's currently being used.' on a certificate that is not being used.

Scope FortiGate, all firmware.
Solution

Sometimes, a local certificate can't be deleted. Even after removing all references, it gives the following error:

 

Entry is used.
Can't delete this certificate. It's currently being used.

Command_cli_delete:6740 delete table entry fgnw unset oper error ret=-23.

 

Upon attempting to delete the certificate through the CLI, the following error appears:

 

Can't delete this certificate. It's currently being used.
command_cli_delete:6740 delete table entry <certificate_name> unset oper error ret=-23
Command fail. Return code -23

 

Kush_Patel_0-1666796508941.png

 

To find out where the certiifcate is being used on Fortigate, run the following commands in the CLI:

 

# config system global

(global) # get | grep fgnw

admin-server-cert   : fgnw

(global) # end

 

In this instance, the certificate is being used as an 'admin server certificate'. This information can be found in the GUI in System -> Settings under the Administration Settings section.

 

Check the value of the 'HTTPS server certificate' field:

 

Kush_Patel_1-1666796544199.png

 

Change the certificate here. After that, the local certificate will be possible to delete.

 

Optionally, download the configuration file and run a search for 'certificate_name' to find where the certificate is being used in the configuration.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!