Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
brianb1
New Contributor

local certs auto regenerating

we have two FG100-F in an HA pair.  several times a day, the secondary FW will seemingly auto regenerate all local Certs.  the users is FGT_ha_admin and method ha_daemon.  we can figure out why this is.  except its causing a lot of unnecessary alerts.  examples from log below: 

TimeeditLogin MethodActionMessage
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL_RSA2048
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL_ECDSA256
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL_ED448
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL_DSA2048
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL_ED25519
5/13/2024 18:18FGT_ha_adminha_daemonEditEdit vpn.certificate.local Fortinet_SSL

 

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello Brian,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
brianb1

guess you lost me here - the firewall is in a passive state - so this is causing it to refresh the certs?  and I'm not sure what your saying to do to prevent that.  thanks

Debbie_FTNT

Hey brianb1,

I haven't seen that before, and I honestly have no idea what could be causing it.

If you want to investigate, I would suggest the following:

- take a configuration backup of the secondary

- wait for the certificate logs to be generated

- take another configuration backup

- compare the before/after backups in an editor

-> that should give you an idea if anything actually changed

 

If something does change, then the question is if anything changes on the primary as well and gets synced to secondary.

If nothing changes, then the question is why those logs are generated - perhaps the logging daemon is stuck in a loop? In that case, a reboot should help straighten it out.

 

Cheers,

Debbie

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors