Skip to main content
nmohamadnassir
Staff
Staff
March 30, 2026

Troubleshooting Tip: Unable to validate VM license - Certificate failed verification. Error: 18 (self-signed certificate)

  • March 30, 2026
  • 0 replies
  • 518 views
Description

This article describes how to resolve issues when FortiGate VM is unable to validate a license with FortiGuard Distribution Services (FDS) when using a web proxy.

Scope FortiGate.
Solution

User will get the output below, indicating license validation failed.

 

upd_daemon[1980]-Received update request from pid=13496
upd_vm_process[602]-last warning 66 seconds ago
do_setup[349]-Starting SETUP
upd_act_setup[126]-Trying Setup, fmg=0
__upd_comm_rcv[1000]-data_len=24, pkg(buf=0x7ffe2b9c798c, sz=8516, pos=0)
__upd_fix_rx_pkg[1019]-Failed, length=24, no res header.
upd_act_setup[137]-Failed receiving setup response, fmg=0, ret=-1
upd_act_setup[149]-Setup failed, fmg=0.
do_setup[353]-SETUP failed

 

Run the debug below to identify the reason why the VM is unable to validate the license.

 

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application update -1
diagnose debug application forticldd -1
diagnose debug enable

 

Output:

 

Screenshot 2026-02-27 095006.png

 

The log indicates that the license validation failure is caused by an SSL certificate verification error.

 

At the time of the connection attempt, the SSL handshake failed due to a self-signed certificate:

 

Error Code 18 – Self-signed certificate

Depth 0 – The failure occurred at the server certificate level

 

This means the virtual machine does not trust the certificate presented by the server because it is self-signed and not issued by a trusted Certificate Authority (CA) in the VM’s trust store.

 

As a result, the SSL connection could not be established, leading to license validation failure.

 

If the certificate (check the certificate 'subject') originates from the proxy server or from any intermediate CA in the chain, these certificates must be properly imported into the FortiGate device.

 

Ensure that the entire certificate chain is loaded so that it is recognized and trusted during the SSL handshake.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!