Skip to main content
candawi
Staff
Staff
October 9, 2025

Troubleshooting Tip: Error messages 'This Firmware image didn't pass the signature verification' and 'Firmware upload failed' when attempting to upgrade firmware image

  • October 9, 2025
  • 0 replies
  • 17996 views

Description

This article describes how to address the errors 'Image upgrade failed. This Firmware image didn't pass the signature verification' and 'Firmware upload failed' when trying to upgrade the firmware image. 

Scope

FortiGate.

Solution

Example error:

 

Picture1 (1).png

 

The user is unable to upgrade firmware even when the checksum of the firmware that has been downloaded from the Customer Service and Support web portal is verified. When checked, the security level of the firewall is set to High.

Security level on the device can be checked using the command output below:

FGT30G-4 # get sys status
Version: FortiGate-30G v7.2.11,build6542,250210 (GA.M)
Current Security Level: High


The method of upgrading the firewall is by File Upload. Even with the use of other browsers, error messages are still the same. When this happens, try to use a different method of upgrading the firmware that is discussed in this article: Technical Tip: How to upgrade FortiGate firmware before proceeding with lowering the BIOS security on a FortiGate via console port.

 

To change the BIOS security level:


Lowering the BIOS security level on a FortiGate device is necessary when downgrading or upgrading to a FortiOS version that does not support BIOS-level signature and file integrity checks. This is because newer BIOS versions (5000100, 6000100, or greater) include enhanced security features that prevent the installation of firmware versions lacking these checks.

By temporarily lowering the security level, users can bypass these restrictions to perform the downgrade or upgrade. However, this action reduces the device's security posture, so it is crucial to restore the security level after completing the firmware change to maintain optimal security.

The signature verification error is expected when a user tries to upgrade FortiGate from v7.2.11-b6542 to v7.2.12-b6666 in FortiGate/FortiWifi 30G and 31G devices when the BIOS security level is set to high (30G Series Upgrade from 7.2.11 to 7.2.12).

Note: The issue is the same even while upgrading from v7.2.11 to v7.2.13.

In a few G-series model devices (entry- to mid-level G-series FortiGates), the security level could be changed only by using Technical Tip: Change security level on FortiGate G series models.

A similar but different error can also be seen when upgrading a FortiGate 30G/31G from v7.4.8 to v7.4.9 or v7.4.10, with an error stating 'expired firmware update license' even though support contracts are still current. If this issue is encountered, see this article: Technical Tip: Failed to upgrade due to 'expired firmware updates license' while upgrading FortiGate 30G/31G from v7.4.8 to v7.4.9 or v7.4.10.

Another similar issue can also be seen while upgrading FortiGate 60F to version 7.6.7 using the GUI.

The error received is:

******WARNING: This firmware failed signature validation.******


A workaround for this is upgrading through CLI or from FortiGuard.

This issue can also be encountered on 2GB units when the unit enters conserve mode during an upgrade process. It is recommended to free up memory before initiating the upgrade.

Starting with FortiOS GA builds v7.0.16, v7.2.9, v7.4.4, v7.6.0, and later releases, FortiGate VM models no longer allow the BIOS security level to be modified after an upgrade. The BIOS security level is fixed at 2 and cannot be changed. changed.

Related article:

Troubleshooting Tip: Unable to boot the firewall or load firmware image

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!