Created on
11-19-2025
09:47 PM
Edited on
11-19-2025
09:50 PM
By
Jean-Philippe_P
| Description |
This article describes the behavior where upgrading in a High Availability configuration removes the Secondary Server certificates. The certificates are no longer listed under System -> Certificate Management for the Secondary.
The behavior occurs if all the following conditions apply:
|
||||||||||||||||||||||||||||||||||||
| Scope |
FortiNAC v F7.6.3, v F7.6.4. |
||||||||||||||||||||||||||||||||||||
| Solution |
Fixed in version F7.6.5.
However, if already running either version F7.6.3 or F7.6.4, then one of the following workarounds must be performed to recover the certificates for the Secondary Server post upgrade.
Workaround Option 1: Post upgrade, install new certificates to the Alias for the Secondary.
Workaround Option 2: Copy the existing Secondary certificate to a temporary alias and re-copy to the original alias post upgrade.
Option 2 Procedure:
Example values: Alias for Secondary Server certificate to be preserved: LOCAL. Primary Hostname: fnac01.nacqa.test. Secondary Hostname: fnac02.nacqa.test.
The procedure is complete. TEMP alias can be deleted, if desired. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.