FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tpatel
Staff
Staff
Article Id 419699
Description This article describes how to resolve the invalid status error for a certificate that occurs when the FortiGate system time is incorrect.
Scope FortiGate.
Solution

On the FortiGate, under System -> Certificates. Several certificate shows an invalid status even with seemingly valid 'From' and 'Expires' dates.

certificate error 1.PNG

 

Inspecting the configuration through the CLI also shows the correct 'Valid From' and 'Valid to' dates.

 

get vpn certificate local details
== [ Fortinet_GUI_Server ]
Name: Fortinet_GUI_Server
Subject: C = US, ST = California, L = Sunnyvale, O = Fortinet Ltd., OU = FortiGate, CN = FortiGate
Issuer: C = US, ST = California, L = Sunnyvale, O = Fortinet, OU = Certificate Authority, CN = FGVMULTM25000090, emailAddress = support@fortinet.com
Valid from: 2025-10-17 15:45:39 GMT
Valid to: 2028-01-20 15:45:39 GMT
Fingerprint: 6A:A8:E0:A7:1D:08:46:B7:8E:05:8E:CF:AF:CB:DF:4E:B8:69:F0:47:4E:A5:B4:C6:46:0B:ED:8C:D8:B7:92:3D
Serial Num: 7f:0e:d3:f1:a3:a4:75:cc

 

This certificate error could appear on the FortiGate because the date on the device is incorrect, leading FortiOS to think that the certificates are outside of their validity period.

 

execute date
current date is: 2000-11-19

 

To resolve this, check that the date and time on the FortiGate are correct. If the system time is configured manually, it must be corrected. If the FortiGate is receiving time from an NTP server, ensure that the FortiGate can connect to the NTP server and obtain the correct date and time.

Related article: 
Troubleshooting Tip: NTP synchronization issue