Created on
08-03-2025
03:27 PM
Edited on
08-08-2025
07:20 AM
By
Stephen_G
Description |
This article describes an issue where provisioning an ACME certificate on a FortiGate HA cluster using the ACME protocol causes the cluster to go out of sync. |
Scope |
FortiOS 7.2.11, 7.4.8 |
Solution |
When configuring a new ACME certificate on a FortiGate HA Cluster on an affected firmware version, the email field in ACME account configuration is incorrectly empty. Since this is not valid configuration, the secondary fails to apply it, causing the HA sync issue.
Since this is a result of invalid configuration not being applied to the secondary, neither recalculating the HA checksums nor restarting the synchronization process restores the sync status to 'in-sync'. execute ha synchronize start The 'email' attribute sent to the secondary unit is an empty string and is non-configurable, which results in the HA cluster going out of sync.
Manual configuration of the missing entries under config system acme and config accounts on the secondary unit is not possible, as these settings are automatically generated on the primary unit.
config system acme
This matches known issue 1170282 for FortiOS v7.2.11 and v7.4.8, listed in FortiOS v7.4.8 Release Notes. Workaround:
Restore the missing configuration on the primary unit in HA cluster following the steps below.
When valid ACME account details are added, this applies the valid ACME configuration, allowing HA configuration to sync to primary and enabling ACME certificate renewal on schedule.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.