As this was the top Google result:Should you generate the p12 user
certificate with openssl 3+ -> IOS requires the use of the -legacy flag
when generating it. Otherwise the Fortigate client will give you the bad
/ wrong passphrase error. openssl pkcs...