Didn't like having to switch to flow mode or accept any invalid certs.
Issue on 6.4.5 (temporarily till FG has a better fix avail.) resolved by
following workaround: 1: verify cert bundle is v28 -> diag autoupdate
versions -> execute update-now 2: ap...