Skip to main content
aquadri
Staff
Staff
March 25, 2026

Troubleshooting Tip: Special characters are not allowed in certificate name

  • March 25, 2026
  • 0 replies
  • 144 views
Description

This article describes an issue where, when creating or importing a certificate on FortiAnalyzer, FortiManager, the following validation error may appear:

 

    Certificate name can only include letters, numbers, '-', '_', and space

Scope FortiAnalyzer, FortiManager.
Solution

When creating or importing a certificate containing special characters in its name such as "@#%&/\!*()." on a FortiManager, FortiAnalyzer, the following error will appear:

 

    Certificate name can only include letters, numbers, '-', '_', and space

 

This occurs when the certificate name contains unsupported characters other than letters, numbers, hyphen '-', underscore '_', space. e.g 'test@test.com'.

 

To resolve this issue:

  1. Edit the certificate name.
  2. Remove any unsupported characters.
  3. Use only letters, numbers, hyphens (-), underscores (_), or spaces.
  4. Save and retry importing the certificate.

 

In certain cases, a certificate already installed on FortiAnalyzer or FortiManager may contain special characters in its name carried over from older firmware versions, which are lost during a firmware upgrade. During the upgrade process, the following message may appear in the console logs.

 

                                  Certificate_Console_Error.png

 

In order to overcome this situation, follow the steps outlined below:

 

  • Prior to the upgrade, access the FortiAnalyzer, FortiManager CLI and execute the following commands:

 

config system certificate local

show

 

  • Copy the certificate named with special characters e.g 'test@test.com'.
  • Create a new certificate via CLI without special characters in its name. For example, use 'test_test_com' (replacing '.' with '_').
  • Paste the parameters from the original certificate into the newly created certificate.
  • Confirm that the new certificate is visible under:
    System Settings -> Certificates -> Local Certificates.
  • If certificate was used for WebUI access, update the certificate in the administrative settings by navigating to:
    System Settings -> Admin -> Admin Settings -> HTTPS & Web Services
    Select the new certificate and select Apply.
  • An 'Unknown Error' message may appear after applying the changes. This is expected due to the certificate update;  refresh the browser to proceed.
  • After completing the above steps, continue with the upgrade by following the recommended upgrade path.

Note that a '-651' error may still appear in the console for the old certificate if still present before upgrade on the device; however, the new certificate will function as expected.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!