Description
This article describes a possible solution when FortiGate VM is unable to create a Lets Encrypt Certificate via CLI or GUI although connectivity from firewall to ACME server appears successful.
Scope
FortiGate.
Solution
diagnose sys acme status-full fw-01.test.net
"when": "Sun, 16 Jun 2024 05:58:59 GMT",
"type": "renewal-error",
"detail": "Unsuccessful in contacting ACME server at <https://acme-v02.api.letsencrypt.org/directory>.
If this problem persists after a reboot, check the network connectivity from the FortiGate to the ACME server (ban on public IP, ISP filtering, routing, etc).
A possible solution is to run the 'diagnose sys acme purge-all' command to wipe the status file clear any internal status for the ACME client and start a new attempt from the FortiGate's configuration. It also restarts the ACME client on FortiGate.
Related article:
Troubleshooting Tip: Let’s Encrypt certificate did not automatically renew
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.