From 15 March 2027 a publicly trusted certificate lasts at most 100 days, and from 15 March 2029 at most 47. If your FortiGate's SSL VPN portal, admin page or captive portal uses a certificate bought from a commercial CA and installed by hand, that's a renewal every three months, then every six weeks. Certificates from your own internal CA aren't covered by these limits.
Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar
Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.
config vpn certificate local, set enroll-protocol acme2 with acme-ca-url, acme-domain and acme-email, after choosing the interface in config system acme.acme-eab-key-id, acme-eab-key-hmac). Fortinet notes that on 7.6.4 and later setting the HMAC can fail with "Invalid EAB HMAC string"; their workaround is to add it to a downloaded config and restore it.acme-renew-window) defaults to 30 days before expiry.If the CA renews with the same key pair, Fortinet documents updating the certificate from the CLI without a new CSR (PEM format). Changing the SSL VPN server certificate disconnects connected VPN users, so do it in a maintenance window. At 100 days that's four windows a year per certificate; put each one on a shared calendar 14 days before expiry, with an owner.
Interfaces only your staff reach (the admin GUI, internal portals) can use a certificate from your own CA, which the 100-day rule doesn't cover, provided the devices that connect trust that CA. Public-facing SSL VPN portals usually need a public certificate.
Every public certificate is in Certificate Transparency logs, including the ones on firewalls. A long-lived certificate from a commercial CA on a vpn. or remote. hostname is almost always a hand-installed one.
Free tool: Free renewal forecast: your public certificates, the manual ones, and a 2027 renewal calendar
Enter a domain; your browser reads public Certificate Transparency logs and builds the list and a calendar file. Nothing goes through our servers.
How do you renew the certificate on your FortiGate today, and what happened the last time it expired or nearly did?
We're researching this problem and read every answer. Tell us what happened (4 short questions, no sign-up; AI tools help us read the answers).