Flatsonar

Fortinet SSLVPN client

by The NetworkManager Developers

Client for Fortinet SSLVPN virtual private networks

Dangerous permissions Unverified publisher GPL-2.0+
Screenshot 1 of Fortinet SSLVPN client Screenshot 2 of Fortinet SSLVPN client

About

Support for configuring Fortinet SSLVPN virtual private network connections.

Permissions

3 permissions weaken the sandbox. Flatsonar asks before installing.

  • access to a sensitive location (~/.gnupg): credentials or autostart
    --filesystem=~/.gnupg:rw
  • smart card readers
    --socket=pcsc
  • your keyring / saved passwords
    --talk-name=org.freedesktop.secrets
  • inter-process communication (needed for X11)
    --share=ipc
  • network
    --share=network
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • Wayland display
    --socket=wayland
  • audio
    --socket=pulseaudio
  • GPU acceleration
    --device=dri
  • access to xdg-config/gnupg
    --filesystem=xdg-config/gnupg:rw
  • access to ~/.pki
    --filesystem=~/.pki:rw
  • access to xdg-config/pki
    --filesystem=xdg-config/pki:rw
  • access to xdg-run/gvfsd
    --filesystem=xdg-run/gvfsd:rw
  • access to /run/.heim_org.h5l.kcm-socket
    --filesystem=/run/.heim_org.h5l.kcm-socket
  • metadata X-DConf=migrate-path=/org/gnome/evolution/
    --metadata=X-DConf=migrate-path=/org/gnome/evolution/
  • notifications
    --talk-name=org.freedesktop.Notifications
  • talks to org.gnome.keyring.SystemPrompter
    --talk-name=org.gnome.keyring.SystemPrompter
  • talks to org.gnome.OnlineAccounts
    --talk-name=org.gnome.OnlineAccounts

Who publishes this

Nobody has confirmed that the publisher controls this app id. Flatsonar warns before installing.

  • packaged by github.com/hekimoghlu, not by the org.gnome namespace owner; it does build the owner's code from https://gitlab.gnome.org/GNOME/evolution-data-server.git
    publisher:namespace
  • fetches from 0pointer.de over unencrypted http: anyone on the path can swap the bytes
    source:insecure-url
  • git source tracks a moving branch: what gets built can change without the manifest changing (x6)
    source:unpinned

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.