Fortinet white logo
Fortinet white logo

Known issues

Known issues

The following issues have been identified in version 7.6.6. To inquire about a particular bug or report a bug, please contact Fortinet Customer Service & Support: https://support.fortinet.com.

Bug ID Description

1271269

FortiWeb generates frequent critical event logs stating "Something is wrong with certificate or certificate revoked, errorno(19)." This results from a certificate validation error during FortiGuard Anycast communication, though FDS updates and other services remain unaffected.

Workaround:

Disable the FortiGuard Anycast option using:

config system fortiguard
    set fortiguard-anycast disable
end
1222647

When the Login Disclaimer banner is enabled, the GUI becomes inaccessible and returns an ERR_EMPTY_RESPONSE error. The issue occurs due to a null pointer condition during cookie handling in the login disclaimer process.

Important: FIPS users are advised not to upgrade to this release, as the login disclaimer cannot be disabled in FIPS mode. Upgrading under these conditions results in loss of GUI access, leaving only SSH and console access available.

1225818

CRL files cannot be restored using the execute backup cert-config and execute restore cert-config commands, and must be manually re-imported after restoring certificate configuration.

Because large CRLs generate substantial encoded data during backup, including them can exceed CMDB capacity and lead to system instability. As a result, these commands intentionally back up and restore only certificate and key objects; the CRL store under /var/log/crl/ remains empty after a restore. Deployments that rely on CRL-based revocation checking will not retain their CRL configuration and may experience incomplete certificate-validation behavior until CRLs are reinstalled.

1222520

When upgrading to FortiWeb 8.0.3 or 7.6.6, the system may display console messages such as:

Parsing error at 'ssl-custom-cipher'. err=1
Parsing error at 'tls13-custom-cipher'. err=1

These messages occur because 8.0.3 and 7.6.6 include changes that eliminate the need for ssl-custom-cipher and tls13-custom-cipher entries when standard cipher categories are used. Older configurations may still contain these settings, and the parser logs errors when rejecting them during the upgrade process.

This behavior is cosmetic and does not affect SSL operation or any existing configuration. The issue appears only during this upgrade, and subsequent upgrades will not display these messages.

Known issues

Known issues

The following issues have been identified in version 7.6.6. To inquire about a particular bug or report a bug, please contact Fortinet Customer Service & Support: https://support.fortinet.com.

Bug ID Description

1271269

FortiWeb generates frequent critical event logs stating "Something is wrong with certificate or certificate revoked, errorno(19)." This results from a certificate validation error during FortiGuard Anycast communication, though FDS updates and other services remain unaffected.

Workaround:

Disable the FortiGuard Anycast option using:

config system fortiguard
    set fortiguard-anycast disable
end
1222647

When the Login Disclaimer banner is enabled, the GUI becomes inaccessible and returns an ERR_EMPTY_RESPONSE error. The issue occurs due to a null pointer condition during cookie handling in the login disclaimer process.

Important: FIPS users are advised not to upgrade to this release, as the login disclaimer cannot be disabled in FIPS mode. Upgrading under these conditions results in loss of GUI access, leaving only SSH and console access available.

1225818

CRL files cannot be restored using the execute backup cert-config and execute restore cert-config commands, and must be manually re-imported after restoring certificate configuration.

Because large CRLs generate substantial encoded data during backup, including them can exceed CMDB capacity and lead to system instability. As a result, these commands intentionally back up and restore only certificate and key objects; the CRL store under /var/log/crl/ remains empty after a restore. Deployments that rely on CRL-based revocation checking will not retain their CRL configuration and may experience incomplete certificate-validation behavior until CRLs are reinstalled.

1222520

When upgrading to FortiWeb 8.0.3 or 7.6.6, the system may display console messages such as:

Parsing error at 'ssl-custom-cipher'. err=1
Parsing error at 'tls13-custom-cipher'. err=1

These messages occur because 8.0.3 and 7.6.6 include changes that eliminate the need for ssl-custom-cipher and tls13-custom-cipher entries when standard cipher categories are used. Older configurations may still contain these settings, and the parser logs errors when rejecting them during the upgrade process.

This behavior is cosmetic and does not affect SSL operation or any existing configuration. The issue appears only during this upgrade, and subsequent upgrades will not display these messages.