Fortinet white logo
Fortinet white logo

Administration Guide

Closed network VM license security

Closed network VM license security

The CMS signature is verified immediately after the license is loaded. This ensures that the license is from FortiCare and confirms the authenticity of the license's contents and contracts, enhancing license integrity and customer trust.

If a valid offline license with a CMS signature is loaded:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Valid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Mar 20 18:47:49 2024
License expires: Fri Aug  2 00:00:00 2024
Expiry: 134
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Signature: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:
  permanent: 2
  subscription: 0
If an old offline license without a CMS signature is loaded:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Invalid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Aug  2 20:18:51 2023
License expires: Fri Aug  2 00:00:00 2024
Expiry: 365
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:   
If an offline license with a modified CMS signature is loaded the license is invalid and there is no signature:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Invalid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Mar 20 18:47:49 2024
License expires: Fri Aug  2 00:00:00 2024
Expiry: 134
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:
  permanent: 2
  subscription: 0

Closed network VM license security

Closed network VM license security

The CMS signature is verified immediately after the license is loaded. This ensures that the license is from FortiCare and confirms the authenticity of the license's contents and contracts, enhancing license integrity and customer trust.

If a valid offline license with a CMS signature is loaded:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Valid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Mar 20 18:47:49 2024
License expires: Fri Aug  2 00:00:00 2024
Expiry: 134
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Signature: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:
  permanent: 2
  subscription: 0
If an old offline license without a CMS signature is loaded:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Invalid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Aug  2 20:18:51 2023
License expires: Fri Aug  2 00:00:00 2024
Expiry: 365
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:   
If an offline license with a modified CMS signature is loaded the license is invalid and there is no signature:
FGVM2VTM22222222# get system status
Version: FortiGate-VM64-KVM v7.6.0,build9999,240524
First GA patch build date: 230509
Security Level: 0
Firmware Signature: not-certified
...
Serial-Number: FGVM2VTM22222222
License Status: Invalid
License Expiration Date: 2024-08-02
VM Resources: 1 CPU/2 allowed, 1992 MB RAM
...
FGVM2VTM22222222# diagnose debug vm-print-license
SerialNumber: FGVM2VTM22222222
CreateDate: Wed Mar 20 18:47:49 2024
License expires: Fri Aug  2 00:00:00 2024
Expiry: 134
UUID: fdbf7aa999999999a9999aa578127e67
Default Contract: FMWR:6:20230802:20240804,ENHN:20:20230802:20240804,...,IPMC:6:20230802:20240804
Key: yes
Cert: yes
Key2: yes
Cert2: yes
Model: 2V (6)
CPU: 2
MEM: 2147483647
VDOM license:
  permanent: 2
  subscription: 0