Skip to main content
Maerre
Explorer III
April 27, 2022
Solved

unable to delete local certificate via GUI and no access to CLI

  • April 27, 2022
  • 5 replies
  • 5822 views

Hi Guys,

 

i need to delete an expired local certificate and upload a new one but the delete botton is grayed out and i've no access to CLI (i access directly to the public ip address), how can i replace it?

if i try to import the new one i'm promped this: "Certificate file is duplicated for CA/LOCAL/REMOTE/CRL cert."

hardware is FortiWiFi 60F Region-E

 

thanks

regards

 

 

Best answer by vdralio

Hi @Maerre ,

 

This error usually appears when:

- Certificate is uploaded in the wrong category.
- Import a certificate without private key material.
- Upload the certificate which is already present.

Can you please delete the existing new certificate and create a new certificate with the private key in the pkcs#12 format then import the certificate:
System -> certificates -> import -> Local Certificate -> PKCS#12 Certificate.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fixing-the-error-Certificate-file-is/ta-p/196187

This is a way how to update without generating a new CSR
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-update-a-local-certificate-installed-on-a/ta-p/198661
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-SSL-certificate-as-a-local/ta-p/192766

Here you can verify and validate a certificate following the article below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Verifying-and-validating-the-accuracy-of-a/ta-p/195631

 

Best Regards,

Vasil

5 replies

Maerre
MaerreAuthor
Explorer III
April 27, 2022

Hi @vdralio 

 

thanks for the tip, i 've deleted the certificate but still have the same error when trying to import it:

 

"Certificate file is duplicated for CA/LOCAL/REMOTE/CRL cert."

vdralio
Staff
vdralioAnswer
Staff
April 27, 2022

Hi @Maerre ,

 

This error usually appears when:

- Certificate is uploaded in the wrong category.
- Import a certificate without private key material.
- Upload the certificate which is already present.

Can you please delete the existing new certificate and create a new certificate with the private key in the pkcs#12 format then import the certificate:
System -> certificates -> import -> Local Certificate -> PKCS#12 Certificate.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Fixing-the-error-Certificate-file-is/ta-p/196187

This is a way how to update without generating a new CSR
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-update-a-local-certificate-installed-on-a/ta-p/198661
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-import-SSL-certificate-as-a-local/ta-p/192766

Here you can verify and validate a certificate following the article below:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Verifying-and-validating-the-accuracy-of-a/ta-p/195631

 

Best Regards,

Vasil

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!