Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
andrejwknd
New Contributor

Lets Encrypt cerficiates aren't created properly

Hi,

I'm having issues generating Let's Encrypt certificates on our FortiGate. We have a connection to Let's Encrypts ACME server, DNS was also checked. Our subdomain resolves to the correct IP address. FortiGate also says that the renewal was successful, however the certificate cannot be used in any service (we are generating a cert for SSL-VPN). When you try to view the details of the cert this is what you get:

get vpn certificate local details SSLVPN 

== [ SSLVPN ] ACME details: Status: Unprovisioned 
Staging status: The certificate for the managed domain has been renewed successfully and can be used (valid since Mon, 08 Sep 2025 12:32:13 GMT). A graceful server restart now is recommended.

We also tried restarting Fortigate, no luck.

How can we troubleshoot this ?

Thank you in advance!

7 REPLIES 7
AEK
SuperUser
SuperUser

Hi Andre

What is the certificate status on the WebUI? Is it valid or pending?

And what do you see as details when you double-click on it?

AEK
AEK
andrejwknd
New Contributor

Hi, the status is unknown, and there are no details when I double click on it.

 

andrejwknd
New Contributor

Hi, the status is unknown, and there are no details when I double click on it.

AEK
SuperUser
SuperUser

Did you follow this guide?

https://docs.fortinet.com/document/fortigate/7.2.0/administration-guide/822087/acme-certificate-supp...

Also did you open ports 80 and 443 on the WAN interface?

Did you disable redirect http to https?

Did you disable https-redirect in "config vpn ssl settings"?

AEK
AEK
andrejwknd
New Contributor

I did try that, didn't help. Is there anything else that I could do to troubleshoot ?

AEK
SuperUser
SuperUser

Try debug it as described in this tech tip then share the output.

https://community.fortinet.com/t5/FortiWeb/Troubleshooting-Tip-Let-s-Encrypt-SSL-troubleshooting/ta-...

AEK
AEK
andrejwknd
New Contributor

Hi, I can't debug it this  way because the command 

diagnose debug application acmed 7

doesn't work. I tried listing out my applications with: 

diagnose debug application ?

and I don't see anything resembling acme or acmed.

The version of my fortigate is: FortiGate-100E v7.2.6,build1575,230926 (GA.F)

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors