Skip to main content
MahmutKarali
Explorer
February 6, 2026
Question

Let's Encrypt certificate error

  • February 6, 2026
  • 3 replies
  • 245 views

Hello everyone,

I want to set up Let's Encrypt and ACME for Fortigate, but I keep getting an error. What could be the reason?


I'm getting the error “Unable to create ce

3 replies

kaman
Staff
Staff
February 8, 2026

Hi MahmutKarali,

Please let us know the exact error message that appears.

Additionally, please refer to the document below, which describes the meaning of the error message 'Error creating a new order :: too many certificates already issued for: <domain.com>' while creating a new ACME certificate.(Let’s Encrypt)

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Meaning-of-the-error-message-Error-creating-a-new/ta-p/218652


Please refer to the below doc also:


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Let-s-Encrypt-certificate-did-not/ta-p/245610


https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-VM-is-unable-to-obtain-Lets/ta-p/292768


If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

MahmutKarali
Explorer
February 10, 2026

2026/02/10 09:40:40 x.x.x.x: Timeout during connect (likely firewall problem)
2026/02/10 09:40:40 Starting challenges for domains: x.x.x.x: Timeout during connect (likely firewall problem), problem: urn:ietf:params:acme:error:connection
2026/02/10 09:40:39 Starting challenges for domains
2026/02/10 09:40:39 Loaded order from staging
2026/02/10 09:40:37 Selecting account to use for x.fortiddns.com
2026/02/10 09:40:37 Driving ACME protocol for renewal of grossvpn.fortiddns.com
2026/02/10 09:40:37 Contacting ACME server for x.fortiddns.com at https://acme-v02.api.letsencrypt.org/directory
2026/02/10 09:40:37 Assessing current status
2026/02/10 09:40:37 Checking staging area

 

 

I'm getting this kind of warning. It would be great to configure this.

funkylicious
SuperUser
SuperUser
February 10, 2026

if you have ports 80 and 443 enable on the WAN and they open when you access xxx.fortiddns.com and no trusted hosts enable, then it should work.

read - https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-ACME-certificate-provisioning/ta-p/362636 

"jack of all trades, master of none"