FortiAuthenticator
FortiAuthenticator provides access management and single sign on.
akanibek
Staff
Staff
Article Id 296316
Description

This article describes an issue when deleting a 'Local Services' certificates in FortiAuthenticator (FAC). For instance, this could be shown:

 

Error.png

 

Local service certificates selected as certificates for cert_eap_server_cert, cert_radsec_server_cert, auth_https_cert, auth_ldap_cert, saml_idp_cert, saml_idp_cert_alt cannot be deleted. Please consider updating the configuration and trying again.

Scope

FortiAuthenticator v6.4.X, FortiAuthenticator v6.5.X.

Solution

This message shows as the certificate object is referenced in other section of FortiAuthenticator and cannot be just removed, as it would leave some services inoperable. Consequently, the references need to be removed from all configurations on FortiAuthenticator.

Below are some of the locations where the certificate can be applied.

  1. System -> Administration -> System Access -> HTTPS Certificate.
  2. Authentication -> RADIUS Service -> Certificates -> EAP Server Certificate | RADSEC Server Certificate.
  3. Authentication -> SAML IdP -> General -> Default IdP Certificate.
  4. Authentication -> SAML IdP -> Service Providers -> <service provider> -> Server Certificate.
  5. Authentication -> LDAP Server Settings -> LDAP Server certificate.
  6. Authentication -> OAuth Service > General -> JWT private key.

 

NoError.png

 

When the references are removed (and replaced with another valid certificate), the certificate object can be removed.