Special notices
If "server certificate validation" of FortiClient is enabled by EMS
If server certificate validation is enabled in FortiClient by EMS, make sure that the certificate in the FortiPAM GUI can be validated by FortiClient.
Use one of the following two options:
-
Option 1: The FortiPAM GUI certificate is signed by the public certificate authority (CA).
-
Option 2: The CA certificate for the FortiPAM GUI is pushed to FortiClient by the EMS, or is manually installed in the Windows certificate store.
To configure the FortiPAM GUI certificate, see Editing an interface in the latest FortiPAM Administration Guide.
To verify whether server certificate validation is enabled in FortiClient, go to Endpoint Profiles > ZTNA Destinations and check the following setting:
<disallow_invalid_server_certificate>0</disallow_invalid_server_certificate>
A value of 0 indicates that server certificate validation is disabled.
Allow pop up windows on Firefox
When launching web applications on the Firefox browser, allow pop up windows.
Web proxy CA certificate
When launching public websites, FortiPAM uses the selected CA certificate to re-sign the public websites.
When launching private websites, FortiPAM will use untrusted CA to re-sign the private websites.
Client software
Before upgrading to FortiPAM 1.8.3, check if there is a software in Secret Settings > Client Software. If yes, reduce the Video Storage Limit / File Storage Limit (in the Advanced tab in System > Settings) to allow uploading software from a USB disk (/data2/pkg) to the video disk.
After upgrading to FortiPAM 1.8.3, adjust the storage limit in the Advanced tab in System > Settings.