Skip to main content
nevan
Staff
Staff
March 17, 2026

Troubleshooting Tip: 'eap_proxy' reloads continuously after certificate bundle upgrade

  • March 17, 2026
  • 0 replies
  • 295 views
Description This article describes the incident that, after upgrading the certificate bundle, the eap_proxy daemon may continuously reload every 2–3 seconds. This behavior may also cause high CPU usage on a single core.
Scope FortiGate 80F/81F, 60F/61F platforms.
Solution

The eap_proxy daemon continuously reloads after upgrading the certificate bundle on certain FortiGate and FortiWiFi platforms. The repeated reload occurs every few seconds and may cause high CPU utilization on a single core. This behavior is caused by a busy loop during daemon shutdown when the WiFi certificate changes.

It can be done automatically with public FDS services or manually with the CLI command 'execute vpn cert ca import bundle <bundle_name> <FTP/TFTP server>'.

When the eap_proxy daemon repeatedly restarts every 2–3 seconds, the crashlog appears as follows:

286: 2023-06-13 14:30:34 the killed daemon is /bin/eap_proxy: status=0x0
287: 2023-06-13 14:30:36 the killed daemon is /bin/eap_proxy: status=0x100
288: 2023-06-13 14:30:38 the killed daemon is /bin/eap_proxy: status=0x0

 

After the upgrade, the message appears 'Update CRDB success', but it also shows repeated termination signals triggered by certificate updates.

FortiWiFi-80F-2R # execute vpn cert ca import bundle CRDB_*.pkg x.x.x.x

Update CRDB success
Done.

FortiWiFi-80F-2R # Wifi cert changed. Exit.
Signal 15 received - terminating
Signal 15 received - terminating
Wifi CA changed. Exit.
ELOOP: remaining socket: sock=7 eloop_data=(nil) user_data=(nil) handler=0x974fc8
ELOOP: remaining socket: sock=8 eloop_data=(nil) user_data=(nil) handler=0x9731e8


The repeated restart loop can cause high CPU usage from the eap_proxy process.

 

Run Time: 0 days, 22 hours and 4 minutes
3U, 0N, 9S, 88I

eap_proxy 890 R 99.9 0.0 6
wad 260 S 0.5 0.2 2
ipshelper 272 S < 0.0 2.1 4

 

But the expected behavior is that when the certificate bundle is upgraded, eap_proxy should reload once and continue running normally.

 

Until the fix version is applied, use one of the following workarounds:

  • Reboot the FortiGate system.
  • Manually terminate the zombie eap_proxy process.


diagnose sys process pidof eap_proxy 

diagnose sys kill 11 <pid>

 

To kill the complete process:

   

fnsysctl killall eap_proxy

 

To confirm that the behaviour is matching and to receive the fix information, it is recommended to open a ticket with the support team by following this page: Support.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!