LocalMachine\My, not in the user store,
+ because the TPM key uses the machine scope of the Microsoft Platform Crypto Provider.
+ Look for the certificate in certlm.msc, not certmgr.msc.
+ The GlobalProtect client searches the machine store by default.
+ See Configure the portal.
+ HARDWARE_ATTESTED with the PKCS#12 format.
+ See Linux options.
+ Yes means that credentials or a client certificate is sufficient.
+ With the certificate profile and the no-auth profile, Yes gives certificate-only authentication.
+ No means that the user must supply a certificate and credentials:
+ the certificate check passes, but then the client asks for a password,
+ which fails against the local database, and the user sees "Invalid username or password".
+