Created on
‎03-05-2025
05:23 AM
Edited on
‎01-05-2026
10:47 PM
By
Jean-Philippe_P
| Description | This article describes why, after upgrading from FortiOS v7.2.11 to v7.6.0 or v7.4.7, local administrator access may be denied if system password-policy was reconfigured to force safer password storage using 'set login-lockout-upon-downgrade enable'. |
| Scope | FortiGate. |
| Solution |
While an upgrade from v7.2.11 to v7.4.7 is not a downgrade, it counts as one for the 'login-lockout-upon-downgrade' setting. This is because v7.4.7 and earlier v7.4 versions do not support the safer password storage change.
Upgrade from v7.2.11 to v7.4.8 or later is not affected by this issue unless the given upgrade path includes v7.4.7.
Resolution: Before upgrading from v7.2.11 to v7.4.7, verify if 'login-lockout-upon-downgrade' is enabled. If this setting was never enabled, no further action is required.
config system password-policy
FortiOS v7.6.3 and later:
config system password-policy
If login-lockout-upon-downgrade was enabled previously: Disable the setting as follows.
config system password-policy
Each administrator must log in and log out once after the configuration change to generate the old version of the stored password.
config system password-policy
Expected lockout behavior: Beginning in FortiOS v7.2.11, v7.4.8, and v7.6.1, the security of locally-stored system administrator passwords has been enhanced in to use PBKDF2 hashing, see Enhanced administrator password security. By default for backward compatibility, the old SHA256 version of the password is also retained. This is reflected in the following setting:
FortiOS v7.2.x, v7.4.x:
config system password-policy
If this setting is enabled, affected administrators will not be able to log in after a downgrade. When enabling the setting, a warning message will appear. To apply the configuration, an administrator must confirm the setting manually.
erbium-kvm147 # config system password-policy erbium-kvm147 (password-policy) # set login-lockout-upon-downgrade enable erbium-kvm147 (password-policy) # end When 'login-lockout-upon-downgrade' is enabled, stored passwords do not immediately change. Instead, the FortiGate will track future administrator login events. Administrators who log in will have the old version of their stored password removed.
Once an administrator account only has the PBKDF2 hashed password, it will not be able to log in if the firewall firmware changes to a version that does not support them.
FortiOS v7.0 and previous firmware branches. FortiOS v7.2.10 and earlier. FortiOS v7.4.7 and earlier. FortiOS v7.6.0.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.