Description | This article describes the behavior change after upgrading the firmware from 6.4.x to 7.0.x in regard to the SSL VPN server certificate. |
Scope | FortiGate. |
Solution |
Once the Fortigate is upgraded to version 7.0.1 or above, the previously used SSL VPN server certificate will not be visible in the GUI or the CLI of the SSL VPN settings page.
- The certificate will appear under the System -> Certificates page, but it cannot be used for SSL VPN.
- When the issue is encountered, check if the SSL VPN server certificate being used is a CA certificate on the previous versions.
- On the Certificates page under System -> Certificates, select the certificate which was used in previous versions i.e., v6.4.x, and select details to verify if the CA flag is set.
- If the CA flag is set meaning this is a CA certificate and on previous versions the CA certificate was allowed to be used as an SSL VPN server certificate but since version 7.0.1 this is now limited i.e. CA certificates are not allowed to be used and this is an expected behavior. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.