Created on
12-17-2023
12:22 PM
Edited on
10-19-2025
07:15 AM
By
Stephen_G
| Description |
This article describes how to resolve situations where DigiCert certificates receive a 'certificate expired' warning |
| Scope | FortiGate. |
| Solution |
Since March 8, 2023, DigiCert has started updating the default public issuance of TLS/SSL certificates to the new public second-generation (G2) root and intermediate CA (ICA) certificate hierarchies.
G2 DigiCert certificates:
The G2 DigiCert CA certificates are present in FortiOS with certificate bundle 1.44 and later, released to FortiGuard in June 2023.
diagnose autoupdate versions | grep -A 6 'Certificate Bundle'
If FortiGate is running older firmware and was either factory reset or has not had internet access for some time, it may still be using an older certificate bundle and not trust DigiCert certificates signed by G2 CA certificates.
Possible Symptoms:
4031 continue the cert failure to get replace msg
Resolution:
To force a certificate bundle update, ensure the device has internet access and run the following command:
execute update-now # wait few minutes
To force FortiOS processes to use the new certificate bundle, run
fnsysctl killall fnbamd diagnose test application wad 99
G1 DigiCert certificates:
The DigiCert G1 root CA and intermediate CA are scheduled to be distrusted by Mozilla on April 15, 2026, and not trusted on FortiOS shortly after.
If the remote server is still using a certificate signed by the DigiCert G1 CA after this date, and the website is intended to be publicly accessible, this should be considered an issue on the remote server side. The service provider can be resolve the issue by applying a server certificate signed by a later generation DigiCert CA.
If needed, the FortiGate can be configured to again trust certificates signed by the DigiCert G1 CA by uploading the root and intermediate CA's manually to the FortiGate, see FortiOS v7.6.4 Administration Guide | CA Certificate. The DigiCert CA certificates can be downloaded from the third-party site DigiCert Knowledge Base | DigiCert Trusted Root Authority Certificates. However, after the remote server has migrated to a certificate signed by a later generation CA, it is recommended to remove the manually uploaded remote CA certificate.
For more details regarding the certificate, see this DigiCert knowledge base article.
Additionally, consider putting the profile in the Flow mode to further verify it is working. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.