Fortinet black logo

Known issues

Known issues

The following issues have been identified in FortiClient (macOS) 7.2.3. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID

Description

814391 When connected to FortiClient Cloud, application signatures block allowlisted applications.

834500

FortiClient fails to block Application Firewall categories when web client category is set to monitor.

834839

Web Filter does not block traffic when proxy mode and Application Firewall are disabled.

879985

Application Firewall fails to block Web.Client category HTTPS traffic.

943703

Application firewall block/allow/monitor based on individual applications does not work as expected.

948718

Block count for Application Firewall is not accurate.

957343 Application Firewall unknown application shows in violation list when FortiClient (macOS) should allow all other unknown applications.
957984 Application Firewall reports violations for network service protocols when it is set to monitor in EMS.
958040 Application Firewall fails to work when connected to IPsec VPN tunnel.
958651 Application Firewall violation list shows violated programs as the same as applications, which is not as accurate as Windows.

Avatar and social login information

Bug ID

Description

777013

Avatar, whether changed or existing, does not show on FortiAnalyzer.

857857

Avatar page goes blank if user logs in with LinkedIn account.

878050 Avatar does not update on FortiOS dashboards and FortiOS cannot show updated information.

954273

After FortiClient upgrades through script, avatar page does not load properly and shows a blank page.

Configuration

Bug ID

Description

730415 FortiClient (macOS) backs up configuration that is missing locally configured zero trust network access (ZTNA) connection rules.

Deployment and installers

Bug ID

Description

764672 FortiClient (macOS) displays deployment popup for user when EMS admin configured unattended installation.
882705 EMS deployment fails if endpoint reboots during deployment package installation process.
935387 Installer downloaded from EMS is not deleted when EMS is changed.

Endpoint control

Bug ID

Description

880167 FortiClient (macOS) cannot register with EMS due to selecting the wrong interface to connect to EMS.
958511 FortiClient (macOS) does not support Microsoft Entra ID (formerly known as Azure Active Directory) verification when joining EMS.
967008 Revoking client certificate from EMS also revokes the EMS CA certificate, which causes unnecessary keychain prompt.

Endpoint management

Bug ID

Description

891264 EMS creates duplicate records for domain-joined Ubuntu endpoints.

Endpoint policy and profile

Bug ID

Description

906951 GUI does not reflect profile changes unless user manually restarts the FortiClient (macOS) console.

Endpoint security

Bug ID

Description

960595 FortiClient (macOS) cannot reach FortiClient Cloud.

FSSOMA

Bug ID

Description

956538

FortiClient (macOS) does not support multiple FortiAuthenticator server addresses.

962067 FortiClient single sign-on mobility agent (FSSOMA) does not work with Apple local account type.

GUI

Bug ID

Description

857148

GUI shows duplicate FortiClient consoles.

902595

SAML prompt flashes on autoconnect.

954876

Backup Comments option does not work.

968068 FortiClient responds slowly and shows blank page when opening GUI.

Installation and upgrade

Bug ID

Description

827939

FortiTray is not open anymore prompt shows when deploying FortiClient using script through mobile device management.

828781 FortiClient (macOS) behaves inconsistently when uninstalling it through commands in terminal and the FortiClientUninstaller GUI tool.

929219

FortiClient is upgradable from full to free version.

951945

Uninstaller shows Install Now prompt instead of Remove now.

955448

Manual upgrade from 7.2.0 removes manually added VPN tunnels.

License

Bug ID

Description

874676 Endpoint is tagged with existing ZTNA host tags for Vulnerability and AV after EMS license is updated from EPP to Remote Access.

Logs

Bug ID

Description

711763

FortiClient does not point to usfgd1.fortigate.com for EMS web profile setting:Location-US | Server-Fortiguard (Legacy).

716803 When logged in as domain user, avatar does not show properly on FortiAnalyzer 7.0.
742124 Sandbox events are not replicated on FortiAnalyzer.

811746

FortiClient (macOS) sends duplicated and old logs to FortiAnalyzer.

872875 Disabling Client-Based Logging When On-Fabric in EMS does not work for macOS endpoints.
951917 The device MAC address field for FortiClient (macOS)-related events under FortiAnalyzer shows 00:00:00:00:00:00 instead of device MAC address.
972658 FortiClient does not send Web Filter logs to FortiAnalyzer.

Malware Protection and Sandbox

Bug ID

Description

551282 Sandbox exception for trusted sources does not work and FortiClient (macOS) uploads files sourced from Apple Inc.
719920 FortiClient cannot submit files downloaded from Thunderbird to FortiClient Cloud Sandbox (PaaS).
755198 FortiClient (macOS) does not submit files downloaded using Edge to Sandbox or Sandbox Cloud.
829415 When next generation antivirus is enabled, FortiClient (macOS) shows real time protection (RTP) as disabled.
837638 Identifying malware and exploits using signatures received from FortiSandbox does not work.

855555

Enabling real-time protection and setting <block_removable_media> to 1 causes FortiClient (macOS) to fail to block a USB device.

855570 Real-time protection (RTP) scans files regardless of the maximum file size setting for scanning files.
859241 FortiSandbox sends files to or queries results from FortiSandbox when EMS is not authorized.
888356 User can stop AV quick/full scan triggered from EMS.
921370 User cannot stop manually triggered AV scan in FortiClient.
949187 Cloud Sandbox fails to work and treats EICAR file as clean.
949258 GUI shows no events under Realtime Protection events.
951380 RTP creates folder when Word and Excel files are saved on network shared drive (NAS).
961542 Enabling Sandbox freezes system.

Onboarding

Bug ID

Description

811976 FortiClient (macOS) may prioritize using user information from authentication user registered to EMS.
872136 User verification period option under User verification does not work as configured.

Quarantine management

Bug ID

Description

868798 Custom quarantine message does not work.

Remote Access

Bug ID

Description

720236 FortiClient (macOS) does not support DH groups 19-21.
738425 SSL VPN GUI and tray have mismatch in unity features.
755199 Button to launch FortiClient from SSL VPN web portal does not work.
772247 SAML authentication times out with SSL VPN.

800529

GUI has issue with Settings > VPN Options > Do not Warn Invalid Server Certificate.

821660

FortiClient (macOS) behaves inconsistently with LDAP user login and autoconnect.

833001

When using FortiAuthenticator as SAML identity provider, autoconnect fails after user logout/relogin.

834198 On an AWS virtual machine, autoconnect does not work and FortiClient displays an Initialize VPN system extension was failed error.
835096 FortiClient (macOS) cannot establish SAML single sign on VPN after Wi-Fi drops or disconnects and user reconnects manually.

851600

SSL VPN connection fails with FQDN resolving to multiple IP addresses when FortiClient (macOS) cannot reach resolved IP address.

854265

SSL VPN connects after sleep.

866971

System Preferences for FortiClient (macOS) network extension is under different name compared to 7.0.7.

870198 FortiClient system keychain has issue while connecting to SSL VPN with system keychain certificate.

Workaround options:

  • Move the FortiClient system keychain to the login keychain.
  • Right-click the private key, select Access Control, then +, then Command + Shift + g. Enter the following path: "/Applications/FortiClient/Contents/Resources/runtime.helper/FortiTray.app". This disables user prompts needed when using the certificate.
870585 When using Okta for SAML VPN authentication, saving password and autoconnect fail to work.
874669 FortiClient does not attempt to connect with redundant SAML VPN gateway if it cannot reach first gateway.
893237 FortiClient (macOS) does not provide chance to reinput password during autoconnect after identity provider password change.
894027 FortiClient on macOS Ventura system proxy with proxy autoconfiguration file does not work with IPsec VPN, but works with SSL VPN.
898971 SSL VPN with SAML drops with Login error. Remote denied the request. error.
917898 Host check policy works as AND operation instead of OR operation.
920908 IPsec VPN password renew prompt differs from SSL VPN prompt.
921191 After VPN is up, FortiClient (macOS) fails to access internal websites.
929577 Resilient SSL VPN connection fails after VPN is up and the first gateway goes down.
941513 DH Group option is mandatory when PFS is disabled.
944870 FortiClient on macOS Ventura breaks DNS when connected to VPN after short period of time.
948566 Enabling local LAN option does not work as expected.
949271 Dialup IPsec VPN split tunnel prefix limit is 200.
951344 VPN cannot recognize certificate with diacritics.
952987 FortiClient (macOS) does not clear IPsec VPN tunnel saved password if connection fails due to wrong credentials.
954004 FortiClient (macOS) cannot establish DTLS tunnel when handshake packet has a large MTU.
954632 IPsec VPN fails to update password in keychain store when trying to renew expired AD password with autoconnect enabled.
961800 When zero trust network access is enabled, pfctl rules affect DNS traffic.
963509 FortiClient (macOS) using certificates gets stuck on Connecting and no SNI received is shown in FortiGate logs.
966405 With FortiGate tunnel-connect-without-reauth enabled, when the authentication timeout is reached, FortiClient (macOS) continues to reconnect and ask for token.
968070 FortiClient (macOS) does not parse <disallow_invalid_server_certificate> attribute.
970489 Application Firewall decreases Internet speed when connecting to IPsec VPN.
971633 SSL VPN fails with certificate authentication when certificate CN is in Chinese.
972004 Enable Invalid Server Certificate Warning option does not work for IPsec VPN with SAML authentication.
972089 VPN is stuck at 98% when connected to iPhone hotspot.
975879 IPsec VPN phase 2 setting NO PFS should not configure/show the DH groups for phase 2.
976220 FortiClient (macOS) does not warn user before starting to connect if user provided empty username and/or password.
976852 IPsec VPN redundancy based on ping speed or TCP RTT sorting method does not work.
977245 FortiClient for macOS 13 fails to autoconnect when endpoint is woken from sleep.
977725 FortiClient split tunnel has limitation.
978155 Application Firewall misbehaves with Epic browser.
978270 DNS fails to apply to IPsec VPN tunnel interface after disabling mode_config in IPsec VPN IKEv1 and setting manual mode.
978792 GUI is stuck in VPN connecting page when VPN is connected.
979345 FortiClient stays connected to IPsec VPN IKEv2 tunnel despite DH group mismatch in phase 2.

Software Inventory

Bug ID

Description

737970 Software Inventory may not properly reflect software changes (adding/deleting) on macOS endpoints.

860954

Sending software inventory list or updates to EMS does not happen in real time.

Vulnerability Scan

Bug ID

Description

771833 FortiClient tags endpoint as vulnerable when EMS administrator has enabled Exclude Application Vulnerabilities Requiring Manual Update from Vulnerability.

Web Filter and plugin

Bug ID

Description

873803 In-browser message does not show after switching device user without system reboot.
875298 Exclusion list does not work properly with regular expressions.
878055 Web access does not work.
898303 Web Filter does not work when administrator pushes extensions through Jamf in mobile device management platform.
918616 Video meetings have lag.
937125 Ping drops when clicking About to update signature.
950119 FortiClient (macOS) does not include ability to sign certificate for Web Filter.
955529 Teams and other applications that use video crash and fail to work.
962343 FortiClient (macOS) does not block unrated sites when it cannot access FortiGuard servers.
971067 FortiClient with Web Filter enabled does not allow login to Netflix account.

Zero Trust tags

Bug ID

Description

794385 FortiClient detects third-party antivirus tag.

Zero Trust Telemetry

Bug ID

Description

951597 If the endpoint is bound to Active Directory, FortiClient (macOS) does not sync with EMS while on VPN.

ZTNA connection rules

Bug ID

Description

853281 FortiClient (macOS) does not show the inline CASB database signatures on the About page.
857909 FortiClient (macOS) does not support enabling encryption for ZTNA TCP forwarding rules acquired form ZTNA service portal.

857999

FortiClient does not support using external browser for SAML authentication for ZTNA rules acquired through service portal.

862921 FortiClient does not show prompt for ZTNA user authentication when form-based method is set under authentication rule/scheme on FortiGate.
864821 ZTNA does not have proper logging for SaaS portals.

905880

ZTNA certificate prompt displays when deploying FortiClient (macOS) with Jamf Pro configuration profiles.

Workaround: enable ZTNA in both on-fabric and off-fabric profile if using both.

938962

FortiClient keeps prompting ztagent wants to sign using key Imported Private Key when selecting Always trust.

944537

Adding ZTNA destinations produces pfctl error.

975845 FortiClient (macOS) does not notify end user that certificate is not trusted for ZTNA connection when <disallow_invalid_server_certificate> is enabled.

Other

Bug ID

Description

950099 Non-admin users cannot trust new Web Filter certificate generated in the system keychain.
950458 FortiGuard Agent crashes on macOS Big Sur 11.7.

Known issues

The following issues have been identified in FortiClient (macOS) 7.2.3. For inquiries about a particular bug or to report a bug, contact Customer Service & Support.

Application Firewall

Bug ID

Description

814391 When connected to FortiClient Cloud, application signatures block allowlisted applications.

834500

FortiClient fails to block Application Firewall categories when web client category is set to monitor.

834839

Web Filter does not block traffic when proxy mode and Application Firewall are disabled.

879985

Application Firewall fails to block Web.Client category HTTPS traffic.

943703

Application firewall block/allow/monitor based on individual applications does not work as expected.

948718

Block count for Application Firewall is not accurate.

957343 Application Firewall unknown application shows in violation list when FortiClient (macOS) should allow all other unknown applications.
957984 Application Firewall reports violations for network service protocols when it is set to monitor in EMS.
958040 Application Firewall fails to work when connected to IPsec VPN tunnel.
958651 Application Firewall violation list shows violated programs as the same as applications, which is not as accurate as Windows.

Avatar and social login information

Bug ID

Description

777013

Avatar, whether changed or existing, does not show on FortiAnalyzer.

857857

Avatar page goes blank if user logs in with LinkedIn account.

878050 Avatar does not update on FortiOS dashboards and FortiOS cannot show updated information.

954273

After FortiClient upgrades through script, avatar page does not load properly and shows a blank page.

Configuration

Bug ID

Description

730415 FortiClient (macOS) backs up configuration that is missing locally configured zero trust network access (ZTNA) connection rules.

Deployment and installers

Bug ID

Description

764672 FortiClient (macOS) displays deployment popup for user when EMS admin configured unattended installation.
882705 EMS deployment fails if endpoint reboots during deployment package installation process.
935387 Installer downloaded from EMS is not deleted when EMS is changed.

Endpoint control

Bug ID

Description

880167 FortiClient (macOS) cannot register with EMS due to selecting the wrong interface to connect to EMS.
958511 FortiClient (macOS) does not support Microsoft Entra ID (formerly known as Azure Active Directory) verification when joining EMS.
967008 Revoking client certificate from EMS also revokes the EMS CA certificate, which causes unnecessary keychain prompt.

Endpoint management

Bug ID

Description

891264 EMS creates duplicate records for domain-joined Ubuntu endpoints.

Endpoint policy and profile

Bug ID

Description

906951 GUI does not reflect profile changes unless user manually restarts the FortiClient (macOS) console.

Endpoint security

Bug ID

Description

960595 FortiClient (macOS) cannot reach FortiClient Cloud.

FSSOMA

Bug ID

Description

956538

FortiClient (macOS) does not support multiple FortiAuthenticator server addresses.

962067 FortiClient single sign-on mobility agent (FSSOMA) does not work with Apple local account type.

GUI

Bug ID

Description

857148

GUI shows duplicate FortiClient consoles.

902595

SAML prompt flashes on autoconnect.

954876

Backup Comments option does not work.

968068 FortiClient responds slowly and shows blank page when opening GUI.

Installation and upgrade

Bug ID

Description

827939

FortiTray is not open anymore prompt shows when deploying FortiClient using script through mobile device management.

828781 FortiClient (macOS) behaves inconsistently when uninstalling it through commands in terminal and the FortiClientUninstaller GUI tool.

929219

FortiClient is upgradable from full to free version.

951945

Uninstaller shows Install Now prompt instead of Remove now.

955448

Manual upgrade from 7.2.0 removes manually added VPN tunnels.

License

Bug ID

Description

874676 Endpoint is tagged with existing ZTNA host tags for Vulnerability and AV after EMS license is updated from EPP to Remote Access.

Logs

Bug ID

Description

711763

FortiClient does not point to usfgd1.fortigate.com for EMS web profile setting:Location-US | Server-Fortiguard (Legacy).

716803 When logged in as domain user, avatar does not show properly on FortiAnalyzer 7.0.
742124 Sandbox events are not replicated on FortiAnalyzer.

811746

FortiClient (macOS) sends duplicated and old logs to FortiAnalyzer.

872875 Disabling Client-Based Logging When On-Fabric in EMS does not work for macOS endpoints.
951917 The device MAC address field for FortiClient (macOS)-related events under FortiAnalyzer shows 00:00:00:00:00:00 instead of device MAC address.
972658 FortiClient does not send Web Filter logs to FortiAnalyzer.

Malware Protection and Sandbox

Bug ID

Description

551282 Sandbox exception for trusted sources does not work and FortiClient (macOS) uploads files sourced from Apple Inc.
719920 FortiClient cannot submit files downloaded from Thunderbird to FortiClient Cloud Sandbox (PaaS).
755198 FortiClient (macOS) does not submit files downloaded using Edge to Sandbox or Sandbox Cloud.
829415 When next generation antivirus is enabled, FortiClient (macOS) shows real time protection (RTP) as disabled.
837638 Identifying malware and exploits using signatures received from FortiSandbox does not work.

855555

Enabling real-time protection and setting <block_removable_media> to 1 causes FortiClient (macOS) to fail to block a USB device.

855570 Real-time protection (RTP) scans files regardless of the maximum file size setting for scanning files.
859241 FortiSandbox sends files to or queries results from FortiSandbox when EMS is not authorized.
888356 User can stop AV quick/full scan triggered from EMS.
921370 User cannot stop manually triggered AV scan in FortiClient.
949187 Cloud Sandbox fails to work and treats EICAR file as clean.
949258 GUI shows no events under Realtime Protection events.
951380 RTP creates folder when Word and Excel files are saved on network shared drive (NAS).
961542 Enabling Sandbox freezes system.

Onboarding

Bug ID

Description

811976 FortiClient (macOS) may prioritize using user information from authentication user registered to EMS.
872136 User verification period option under User verification does not work as configured.

Quarantine management

Bug ID

Description

868798 Custom quarantine message does not work.

Remote Access

Bug ID

Description

720236 FortiClient (macOS) does not support DH groups 19-21.
738425 SSL VPN GUI and tray have mismatch in unity features.
755199 Button to launch FortiClient from SSL VPN web portal does not work.
772247 SAML authentication times out with SSL VPN.

800529

GUI has issue with Settings > VPN Options > Do not Warn Invalid Server Certificate.

821660

FortiClient (macOS) behaves inconsistently with LDAP user login and autoconnect.

833001

When using FortiAuthenticator as SAML identity provider, autoconnect fails after user logout/relogin.

834198 On an AWS virtual machine, autoconnect does not work and FortiClient displays an Initialize VPN system extension was failed error.
835096 FortiClient (macOS) cannot establish SAML single sign on VPN after Wi-Fi drops or disconnects and user reconnects manually.

851600

SSL VPN connection fails with FQDN resolving to multiple IP addresses when FortiClient (macOS) cannot reach resolved IP address.

854265

SSL VPN connects after sleep.

866971

System Preferences for FortiClient (macOS) network extension is under different name compared to 7.0.7.

870198 FortiClient system keychain has issue while connecting to SSL VPN with system keychain certificate.

Workaround options:

  • Move the FortiClient system keychain to the login keychain.
  • Right-click the private key, select Access Control, then +, then Command + Shift + g. Enter the following path: "/Applications/FortiClient/Contents/Resources/runtime.helper/FortiTray.app". This disables user prompts needed when using the certificate.
870585 When using Okta for SAML VPN authentication, saving password and autoconnect fail to work.
874669 FortiClient does not attempt to connect with redundant SAML VPN gateway if it cannot reach first gateway.
893237 FortiClient (macOS) does not provide chance to reinput password during autoconnect after identity provider password change.
894027 FortiClient on macOS Ventura system proxy with proxy autoconfiguration file does not work with IPsec VPN, but works with SSL VPN.
898971 SSL VPN with SAML drops with Login error. Remote denied the request. error.
917898 Host check policy works as AND operation instead of OR operation.
920908 IPsec VPN password renew prompt differs from SSL VPN prompt.
921191 After VPN is up, FortiClient (macOS) fails to access internal websites.
929577 Resilient SSL VPN connection fails after VPN is up and the first gateway goes down.
941513 DH Group option is mandatory when PFS is disabled.
944870 FortiClient on macOS Ventura breaks DNS when connected to VPN after short period of time.
948566 Enabling local LAN option does not work as expected.
949271 Dialup IPsec VPN split tunnel prefix limit is 200.
951344 VPN cannot recognize certificate with diacritics.
952987 FortiClient (macOS) does not clear IPsec VPN tunnel saved password if connection fails due to wrong credentials.
954004 FortiClient (macOS) cannot establish DTLS tunnel when handshake packet has a large MTU.
954632 IPsec VPN fails to update password in keychain store when trying to renew expired AD password with autoconnect enabled.
961800 When zero trust network access is enabled, pfctl rules affect DNS traffic.
963509 FortiClient (macOS) using certificates gets stuck on Connecting and no SNI received is shown in FortiGate logs.
966405 With FortiGate tunnel-connect-without-reauth enabled, when the authentication timeout is reached, FortiClient (macOS) continues to reconnect and ask for token.
968070 FortiClient (macOS) does not parse <disallow_invalid_server_certificate> attribute.
970489 Application Firewall decreases Internet speed when connecting to IPsec VPN.
971633 SSL VPN fails with certificate authentication when certificate CN is in Chinese.
972004 Enable Invalid Server Certificate Warning option does not work for IPsec VPN with SAML authentication.
972089 VPN is stuck at 98% when connected to iPhone hotspot.
975879 IPsec VPN phase 2 setting NO PFS should not configure/show the DH groups for phase 2.
976220 FortiClient (macOS) does not warn user before starting to connect if user provided empty username and/or password.
976852 IPsec VPN redundancy based on ping speed or TCP RTT sorting method does not work.
977245 FortiClient for macOS 13 fails to autoconnect when endpoint is woken from sleep.
977725 FortiClient split tunnel has limitation.
978155 Application Firewall misbehaves with Epic browser.
978270 DNS fails to apply to IPsec VPN tunnel interface after disabling mode_config in IPsec VPN IKEv1 and setting manual mode.
978792 GUI is stuck in VPN connecting page when VPN is connected.
979345 FortiClient stays connected to IPsec VPN IKEv2 tunnel despite DH group mismatch in phase 2.

Software Inventory

Bug ID

Description

737970 Software Inventory may not properly reflect software changes (adding/deleting) on macOS endpoints.

860954

Sending software inventory list or updates to EMS does not happen in real time.

Vulnerability Scan

Bug ID

Description

771833 FortiClient tags endpoint as vulnerable when EMS administrator has enabled Exclude Application Vulnerabilities Requiring Manual Update from Vulnerability.

Web Filter and plugin

Bug ID

Description

873803 In-browser message does not show after switching device user without system reboot.
875298 Exclusion list does not work properly with regular expressions.
878055 Web access does not work.
898303 Web Filter does not work when administrator pushes extensions through Jamf in mobile device management platform.
918616 Video meetings have lag.
937125 Ping drops when clicking About to update signature.
950119 FortiClient (macOS) does not include ability to sign certificate for Web Filter.
955529 Teams and other applications that use video crash and fail to work.
962343 FortiClient (macOS) does not block unrated sites when it cannot access FortiGuard servers.
971067 FortiClient with Web Filter enabled does not allow login to Netflix account.

Zero Trust tags

Bug ID

Description

794385 FortiClient detects third-party antivirus tag.

Zero Trust Telemetry

Bug ID

Description

951597 If the endpoint is bound to Active Directory, FortiClient (macOS) does not sync with EMS while on VPN.

ZTNA connection rules

Bug ID

Description

853281 FortiClient (macOS) does not show the inline CASB database signatures on the About page.
857909 FortiClient (macOS) does not support enabling encryption for ZTNA TCP forwarding rules acquired form ZTNA service portal.

857999

FortiClient does not support using external browser for SAML authentication for ZTNA rules acquired through service portal.

862921 FortiClient does not show prompt for ZTNA user authentication when form-based method is set under authentication rule/scheme on FortiGate.
864821 ZTNA does not have proper logging for SaaS portals.

905880

ZTNA certificate prompt displays when deploying FortiClient (macOS) with Jamf Pro configuration profiles.

Workaround: enable ZTNA in both on-fabric and off-fabric profile if using both.

938962

FortiClient keeps prompting ztagent wants to sign using key Imported Private Key when selecting Always trust.

944537

Adding ZTNA destinations produces pfctl error.

975845 FortiClient (macOS) does not notify end user that certificate is not trusted for ZTNA connection when <disallow_invalid_server_certificate> is enabled.

Other

Bug ID

Description

950099 Non-admin users cannot trust new Web Filter certificate generated in the system keychain.
950458 FortiGuard Agent crashes on macOS Big Sur 11.7.