Description | This article explains an issue where a FortiGate certificate cannot be deleted because it's attached to a 'Web Proxy Global' reference that cannot be deleted. An explanation of how to delete the certificate is provided. |
Scope | Any supported version of FortiGate. |
Solution |
Upon attempting to delete a FortiGate certificate, an issue may occur where the certificate cannot be deleted because it is connected to a 'Web Proxy Global' reference. Additionally, there is no option to edit or delete the reference in question.
The certificate in this setting is used for choosing which certificate is used by FortiGate to sign a block page in explicit proxy. This can only be changed through the CLI with the following commands: # config web-proxy global set ssl-cert “<certificate to delete>” <-- Change this to any other certificate set ssl-ca-cert “<certificate to delete>” <-- Change this to any other certificate
# show full-configuration | grep ‘certificate_name’
# config vpn certificate ca | local | remote delete ‘certificate_name’
If the issue persists, contact Fortinet support. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.