Fortinet white logo
Fortinet white logo

Special notices

Special notices

FortiGuard Anycast Certificate Expiration

FortiClient (Linux) 7.0.13 fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers, which results in failed communication for the following updates:

  • Web Filter rating
  • Video Filter rating
  • Split VPN using ISDB
  • Signature and engine updates

See CSB-260303-1 for more information.

ZTNA certificates

Zero trust network access (ZTNA) certificate provisioning requires Trusted Platform Module (TPM) 2.0 on the endpoint with one of the following:

  • Maximum of TLS 1.2 in FortiOS
  • Maximum of TLS 1.3 in FortiOS if the TPM 2.0 implementation in the endpoint supports RSA PSS signatures

For ZTNA tags for checking certificates, FortiClient (Linux) does not check user certificates and only checks root certificate authority certificates installed on the system. These routes are:

Operating system

Route

Ubuntu

/etc/ssl/certs/ca-certificates.crt

  • CentOS
  • Red Hat

/etc/pki/tls/certs/ca-bundle.crt

Special notices

Special notices

FortiGuard Anycast Certificate Expiration

FortiClient (Linux) 7.0.13 fails to recognize the newly issued April 16, 2026 Digicert CA used by FortiGuard Anycast servers, which results in failed communication for the following updates:

  • Web Filter rating
  • Video Filter rating
  • Split VPN using ISDB
  • Signature and engine updates

See CSB-260303-1 for more information.

ZTNA certificates

Zero trust network access (ZTNA) certificate provisioning requires Trusted Platform Module (TPM) 2.0 on the endpoint with one of the following:

  • Maximum of TLS 1.2 in FortiOS
  • Maximum of TLS 1.3 in FortiOS if the TPM 2.0 implementation in the endpoint supports RSA PSS signatures

For ZTNA tags for checking certificates, FortiClient (Linux) does not check user certificates and only checks root certificate authority certificates installed on the system. These routes are:

Operating system

Route

Ubuntu

/etc/ssl/certs/ca-certificates.crt

  • CentOS
  • Red Hat

/etc/pki/tls/certs/ca-bundle.crt