FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
lmarinovic
Staff
Staff
Article Id 195508

Description

 

This article describes the officially supported upgrade path for FortiAuthenticator.

 

Be aware that downgrading will reset the FortiAuthenticator settings to FACTORY-DEFAULT.
FortiAuthenticator can only be reverted to a previous working version by restoring an existing config backup.
It is recommended to create a config backup before performing each upgrade.

 

Scope

 

FortiAuthenticator.


Solution

 

Before upgrading it is recommended to research the Release Notes and check for Known Issues and New Features.
 
Release Notes state provide information about which FortiAuthenticator models are supported and which firmware releases it is supported to upgrade from.


The following are the supported upgrade paths for FortiAuthenticator:

 

  • 6.2.1-6.5.5 -> 6.6.2.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.6.2.
  • 6.0.7 -> 6.6.2.
  • 6.2.1-6.5.4 -> 6.6.1.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.6.1.
  • 6.0.7 -> 6.6.1.
  • 6.2.1-6.5.4 -> 6.6.0.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.6.0.
  • 6.0.7 -> 6.6.0.
  • 6.2.1-6.5.3 -> 6.5.5.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.5.
  • 6.0.7 -> 6.5.5.
  • 6.2.1-6.5.3 -> 6.5.4.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.4.
  • 6.0.7 -> 6.5.4.
  • 6.2.1-6.5.2 -> 6.5.3.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.3.
  • 6.0.7 -> 6.5.3.
  • 6.2.1-6.5.1 -> 6.5.2.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.2.
  • 6.0.7 -> 6.5.2.
  • 6.2.1.
  • 6.5.0 -> 6.5.1.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.1.
  • 6.0.7 -> 6.5.1.
  • 6.2.1-6.4.6 -> 6.5.0.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.5.0.
  • 6.0.7 -> 6.5.0.
  • 6.2.1-6.3.x -> 6.4.X.
  • 6.1.0-6.2.0 -> 6.3.3 -> 6.4.X.
  • 6.0.7 -> 6.4.X.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.0.5 -> 6.0.7 -> 6.4.X.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.3.3.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.3.2.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.3.1.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.3.0.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.2.1.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.2.0.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.1.2.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4 -> 6.1.1.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.4.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 6.0.3.
  • 3.2.1 -> 3.3.0 -> 4.0.0 -> 5.5.0.

FortiAuthenticator 6.6.2.

 

FortiAuthenticator 6.6.2 build 1669 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.6.2, else the following message will be displayed:Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.6.2 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.6.2.

  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.6.2 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 
  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent, or admin UI. If this signing algorithm is used, see to change the certificate prior to the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator 6.6.1.

 

FortiAuthenticator 6.6.1 requires at least 4GB of RAM.

 

FortiAuthenticator 6.6.1 build 1660 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.6.1, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.6.1 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.6.1.

  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.6.1 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 

  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent or admin UI. If this signing algorithm is used, see to change the certificate prior to the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator 6.6.0.

 

FortiAuthenticator 6.6.0 requires at least 4GB of RAM.

 

FortiAuthenticator 6.6.0 build 1617 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.6.0, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.6.0 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.6.0.

  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.6.0 directly.

  • Keep in mind that SHA1 signing algorithms are no longer supported as per release notes. 

  • These certificates can be used in LDAP, SAML, Syslog, SCEP/CMP, SSO Mobility agent, or admin UI. If this signing algorithm is used, see to change the certificate prior to the upgrade. Upgrading without doing so may severely impact the environment.

 

FortiAuthenticator 6.5.5.

 

FortiAuthenticator 6.5.5 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.5 build 1385 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.5, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.5 directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.5
  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.5 directly.

 

FortiAuthenticator 6.5.4.

 

FortiAuthenticator 6.5.4 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.4 build 1377 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.4, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.4 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.4.

  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.4 directly.

 

FortiAuthenticator 6.5.3.

 

FortiAuthenticator 6.5.3 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.3 build 1355 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.3, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.

  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.3 directly.

  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.3.

  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.3 directly.

 

FortiAuthenticator 6.5.2.

 

FortiAuthenticator 6.5.2 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.2 build 1329 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.2. Otherwise, the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance's.
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.2 directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.2.
  • If currently running FortiAuthenticator 6.2.1 or later, upgrade to 6.5.2 directly.

 

FortiAuthenticator 6.5.1.

 

FortiAuthenticator 6.5.1 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.1 build 1295 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.1, else the following message will be displayed: Image validation failed: The firmware image model number is different from the appliance.
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.1 directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.1.
  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.1 directly.


FortiAuthenticator 6.5.0.

 

FortiAuthenticator 6.5.0 requires at least 4GB of RAM.

 

FortiAuthenticator 6.5.0 build 1286 officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.5.0. Otherwise, the following message will display: 'Image validation failed: The firmware image model number is different from the appliance's.'
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.5.0 directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.5.0.
  • If currently running FortiAuthenticator 6.2.1 or later, then upgrade to 6.5.0 directly.


FortiAuthenticator 6.4.X.

 

FortiAuthenticator 6.4.X officially supports upgrades from previous versions by following these supported FortiAuthenticator upgrade paths:

  • If currently running FortiAuthenticator 6.0.5 or older, first upgrade to 6.0.7, then upgrade to 6.4.X. Otherwise, the following message will display: 'Image validation failed: The firmware image model number is different from the appliances.'
  • If currently running FortiAuthenticator 6.0.7, then upgrade to 6.4.X directly.
  • If currently running FortiAuthenticator between 6.1.0 and 6.2.0, first upgrade to 6.3.3, then upgrade to 6.4.X.
  • If currently running FortiAuthenticator between 6.2.1 and 6.3.x, then upgrade to 6.4.X directly.

 

FortiAuthenticator 6.4.X supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 300F.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  •  FortiAuthenticator 800F.
  •  FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator 6.3.3.

 

FortiAuthenticator 6.3.3 build 0692 officially supports upgrades from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.3.3.


FortiAuthenticator 6.3.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).


FortiAuthenticator 6.3.2.

FortiAuthenticator 6.3.2 build 0687 officially supports upgrades from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.3.2.


FortiAuthenticator 6.3.2 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 300F.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

FortiAuthenticator 6.3.1.

FortiAuthenticator 6.3.1 build 0682 officially supports upgrade from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.3.1.

FortiAuthenticator 6.3.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 400E.
  • FortiAuthenticator 1000D.
  • FortiAuthenticator 2000E.
  • FortiAuthenticator 3000D.
  • FortiAuthenticator 3000E.
  • FortiAuthenticator 800F.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator 6.3.0.

FortiAuthenticator 6.3.0 build 0670 officially supports upgrade from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.3.0.

FortiAuthenticator 6.3.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  •  FortiAuthenticator 800F.
  •  FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator 6.2.1.

FortiAuthenticator 6.2.1 build 0552 officially supports upgrades from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.2.1.

FortiAuthenticator 6.2.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  •  FortiAuthenticator 800F.- FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, Oracle OCI, and Alibaba Cloud).

 

FortiAuthenticator 6.2.0.

FortiAuthenticator 6.2.0 build 0542 officially supports upgrades from FortiAuthenticator 6.0.4 and higher.
All other versions of FortiAuthenticator must first be upgraded to 6.0.4 or above before upgrading to 6.2.0.

FortiAuthenticator 6.2.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  •  FortiAuthenticator 800F.- FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).

FortiAuthenticator 6.1.2.

FortiAuthenticator 6.1.2 build 0420 officially supports upgrades from FortiAuthenticator 6.0.4 and higher.
All earlier versions of FortiAuthenticator must first be upgraded to 6.0.4 before upgrading to 6.1.2.

FortiAuthenticator 6.1.2 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).


FortiAuthenticator 6.1.1.

FortiAuthenticator 6.1.1 build 0413 officially supports upgrades from FortiAuthenticator 6.1.0 and 6.0.4.
All other versions of FortiAuthenticator have to first be upgraded to 6.0.4 before upgrading to 6.1.1, otherwise the following message will be displayed:

Image validation failed: The firmware image model number is different from the appliance's.
When upgrading existing KVM and Xen virtual machines to FortiAuthenticator 6.1.1 from FortiAuthenticator 6.0.4, increase first  the size of the virtual hard disk drive containing the operating system image (not applicable for AWS & OCI Cloud Marketplace upgrades).

See the release notes for more details.

FortiAuthenticator 6.1.1 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  • FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, Azure, AWS, and Oracle OCI).


FortiAuthenticator 6.0.4.

FortiAuthenticator 6.0.4 build 0059 officially supports upgrades from all versions of FortiAuthenticator 4.x, 5.x, and 6.0.x.
All prior versions have to be upgraded to FortiAuthenticator 6.0.4 before they can upgrade to FortiAuthenticator 6.1.0 and later.

FortiAuthenticator 6.0.4 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, AWS, Azure, and OCI).


FortiAuthenticator 6.0.3.

FortiAuthenticator 6.0.3 build 0058 officially supports upgrades from all versions of FortiAuthenticator 4.x, 5.x, and 6.0.x.

FortiAuthenticator 6.0.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  • ForiAuthenticator VM (VMWare, Hyper-V, KVM, Xen, AWS, Azure, and OCI).


FortiAuthenticator 5.5.0.

FortiAuthenticator™ 5.5.0 build 0366 officially supports upgrades from all versions of FortiAuthenticator™ 4.x.x and 5.x.x.

FortiAuthenticator™ 5.5.0 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 200E.
  •  FortiAuthenticator 400C.
  •  FortiAuthenticator 400E.
  •  FortiAuthenticator 1000C.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 2000E.
  •  FortiAuthenticator 3000D.
  •  FortiAuthenticator 3000E.
  • FortiAuthenticator VM (VMWare, Hyper-V, KVM, and Xen).

 
Upgrading the FortiAuthenticator 3000D from 4.0.x to 4.1.x is not supported.

The workaround for this model is to upgrade from any 4.0.x version directly to 4.2.0 or higher (skipping all 4.1.x versions).

If install 4.1.x firmware is on a FortiAuthenticator 3000D it stops responding.
The system can run again by restoring valid firmware using the TFTP boot process.
FortiAuthenticator 4.0.0.

FortiAuthenticator™ 4.0 build 0008 officially supports an upgrade from FortiAuthenticator v3.3.

FortiAuthenticator™ 4.0 supports.

  • FortiAuthenticator 200D.
  • FortiAuthenticator 400C.
  • FortiAuthenticator 1000C.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 3000B.
  •  FortiAuthenticator 3000D.
  • FortiAuthenticator VM (VMWare & Hyper-V).

 
FortiAuthenticator™ 4.0 build 0008 does not support upgrades from releases prior to FortiAuthenticator 3.3.

Upgrade via FortiAuthenticator 3.3, following instructions shown in the relevant firmware release notes.

FortiAuthenticator 3.3.

FortiAuthenticator™ 3.3 build 0176 officially supports upgrade from FortiAuthenticator v3.0

FortiAuthenticator™ 3.3 supports:

  • FortiAuthenticator 200D.
  • FortiAuthenticator 400C.
  •  FortiAuthenticator 1000C.
  •  FortiAuthenticator 1000D.
  •  FortiAuthenticator 3000B.
  •  FortiAuthenticator 3000D.
  • FortiAuthenticator VM (VMWare & Hyper-V).


FortiAuthenticator 3.3 build 0176 does not support upgrades from releases before FortiAuthenticator 3.0.
Upgrade via FortiAuthenticator 3.0, following instructions shown in the relevant firmware release notes from the support portal.

Related Article:

Technical Tip: How to upgrade a FortiAuthenticator HA cluster