Skip to main content
heyyo
Explorer III
January 17, 2025
Question

Built in Cert no Renewing even after running the command

  • January 17, 2025
  • 2 replies
  • 1495 views

Hi,

 

I hope you can help me.

 

Followed this KB: Renew Certificate Expired on FortiGate - Fortinet Community

Run #execute vpn certificate local generate default-ssl-key-certs

entered 'y' to confirm, but I am still seeing that the built-in cert is expired in System --> Certificates

 

The system time is same with my timezone.

I can reach FortiGuard servers.

Unit is in stand alone mode.

 

Is there anything else which I need to look into?

 

Thank you very much!

 

2 replies

firacode
New Member
January 17, 2025

If you're still seeing the expired built-in certificate after running the execute vpn certificate local generate default-ssl-key-certs command, try removing the expired certificate manually from System -> Certificates and then regenerate the certificate. Afterward, reboot the FortiGate device to ensure the new certificate is applied. Check your SSL-VPN or other related configurations to make sure they are using the updated certificate. If the issue persists, review the FortiGate logs for errors during the certificate generation process, as it may provide additional insights.

ametkola
Staff
Staff
January 17, 2025

Hello @heyyo ,

 

If executing the commands still didn't helped to renew the built-in certificates you can try to perform both two commands as below :

 

#exec vpn certificate local generate default-ssl-key-certs

#exec vpn certificate local generate default-ssl-serv-key

 

Try to access the fortigate GUI through another browser and check again the status. Usually, the built-in certificate cannot be deleted from the firewall.

 

Best regards,

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!