FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
samandeep
Staff
Staff
Article Id 271225

 

Description

This article describes how to fix a working EMS certificate error after upgrading the FortiGate firmware.

Scope

FortiGate v6.x.x and v7.x.x.

Solution

It is not common that after upgrading the FortiGate Firmware, a FortiEMS connectivity issue where the Forticlient EMS is accessible but getting 'EMS certificate not trusted'.

 

samandeep_0-1693448100595.png

 

In that scenario, use the command to 'unverify' the certificate;

 

execute fctems unverify <FortiClient EMS>

 

Verify the FortiClient EMS again:

 

execute fctems verify <FortiClient EMS>

 

After the verification, the new certificate request will be visible to use on CLI. Press 'Y' for yes.

 

To check the certificate status:

    execute fctems is-verified <Forticlient EMS>

Related articles:
Troubleshooting Tip: EMS certificate not trusted with customized certificate 
Technical Tip: EMS Certificate is not trusted with FortClient EMS Cloud