FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
_mribwan
Staff
Staff
Article Id 388146
Description This article provides more information on hardware-unique certificates: Fortinet_Factory, Fortinet_Factory_Backup, Fortinet_Wifi.
Scope FortiGate.
Solution

The 3 certificates: Fortinet_Factory, Fortinet_Factory_Backup, Fortinet_Wifi are all unique to each hardware.

 

Local certificate.png


Aside from Fortinet_Wifi, which is regenerated upon firmware upgrade (Technical Tip: Fortinet_Wifi certificate expiration), Fortinet_Factory, Fortinet_Factory_Backup cannot able to be regenerated. 

 

As all 3 certificates are unique to each hardware, they do not exist on the backup config as well. This means that the certificates are not transferable from one unit to another by restoring the backup config.

 

Note: In a HA environment, the secondary unit will sync these certificates with the Serial Number from the Primary unit.