Hello,
The Default-Server-Certificate expiration will expire in 5 days.
We use FAC for WIFI EAP-TLS and VPN MFA.
I can see that the certificat is used in LDAP service, OAuth service and maybe in other services.
It is safe to keep using this certificate after the expiration, or should i renew it ? i wanna also the impact if i renew the certificate.
Hi Simo
This certificate is self signed, so it is already not trusted by any equipment, so I guess you are forcing all your equipment to trust it.
You should create your own CA (if not already done) that will sign all you certificates.
Regarding your question, after the expiration you will probably have problems with some equipment, since most of the modern equipment that follow minimum security standards reject the expired certificates.
Hello @AEK
I can see a GPO on my domain controller that force computers to trust the FAC root CA.
Is renewing the expired certificate may cause an impact on our production or it will be transparent ?
Create a new certificate signed with the same CA and install it with its private key on a non-critical equipment, then try use it and see if it has any impact.
It shouldn't have any impact but testing like suggested above is safer before deploying on critical equipment.
Hello @AEK
I think there is a misunderstanding.
The FAC internal CA certificate will not expire until 2032.
The only certificate that is expiring in 5 days is the default-server-certificate.
I don’t see any reason to generate a new CA certificate in this case.
| User | Count |
|---|---|
| 2881 | |
| 1446 | |
| 843 | |
| 822 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.