Good list of fixes, including one I've been waiting for:
Fixed:
412987 IPsec VPN certificate not validated against PKI user’s CN and Subject.
But "If you have configured IPsec in version 5.4.5, do not upgrade to version 5.6.0 because IPsec tunnel cannot be established in version 5.6.0." makes me concerned.
And it looks like anybody with a 100E or 101E might want to wait this one out due to:
Known Issue:
FortiGate-100E / 101E416678 Multiple reports of firewall lockups in production.
If people upgrade to 5.4.5 or run lab tests, please let us know how it goes, what works, what breaks, etc.