Skip to main content
SimoSimo77
New Member
December 2, 2025
Solved

FortiAuthentication GUI keep use the old HTTPS Certificate

  • December 2, 2025
  • 7 replies
  • 727 views

Hello,

 

My FortiAuthenticator HTTPS certificate is close to expiring. I generated a new certificate with the same configuration and imported it through the Local Services console. The old certificate was automatically replaced by the new one, but I can see that the Web GUI is still using the old certificate.

 

I cleaned the browser cache, i tried with the incognito browser mode but nothing works, i also waiting for one but still use the old certificate.

 

I would also like to know whether this certificate has any impact on EAP WiFi authentication or any other FortiAuthenticator components.

 

Thank you.

Best answer by SimoSimo77

Hello,

I had to reboot the HA cluster devices.

No services were impacted during the operation.

Thank you.

7 replies

funkylicious
SuperUser
SuperUser
December 2, 2025

hi,

try diagnose web restart

"jack of all trades, master of none"
SimoSimo77
New Member
December 3, 2025

Hi @funkylicious,

 

I will give a try, thank you.

kaholpa3
New Member
December 2, 2025

Same message in FireFox "Unable to Connect". I can ping the DMZ interface IP. I never set an allow list. If I go to config system admin, edit admin, get. All trustedhost entries are 0.0.0.0 0.0.0.0

AEK
SuperUser
SuperUser
December 2, 2025

Hi Simo

Which FAC version?

Did you select the GUI certificate from the below location? If not then redo from the below location and validate.

 

fac_cert.png

 

 
AEK
SimoSimo77
New Member
December 3, 2025

Hi @AEK 

 

 

We are using FAC v6.4.1.

 

The certificate was already selected, and I also tried re-applying the same settings, but it didn’t fix the issue.

 

I performed a test on version 6.6.7, and in that version the certificate was switched instantly without any problem.



fac.png

 

 

AEK
SuperUser
SuperUser
December 3, 2025

Hello Simo

6.4.1 is not mature and has many known issues.

If you want to stay at 6.4.x then I recommend to update to 6.4.10. You can update it directly according to upgrade path.

https://docs.fortinet.com/document/fortiauthenticator/6.4.10/release-notes/859240/upgrade-instructions#Upgrade_instructions

Hope it helps.

AEK
SimoSimo77
SimoSimo77AuthorAnswer
New Member
December 31, 2025

Hello,

I had to reboot the HA cluster devices.

No services were impacted during the operation.

Thank you.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.