Issue
On some devices managed by Intune, a device management (MDM) tool your IT team may use, running a DocGen package shows a browser pop-up asking for a client certificate. This has been seen on both Mac and iPad. The prompt may reference apps.drawloop.com or na2.docgen.nintex.io. The available certificates are rejected, and the browser shows ERR_BAD_SSL_CLIENT_AUTH_CERT. This has been seen in Safari, Chrome and Firefox. It does not occur on unmanaged devices.
If you're not sure whether your device is managed, your IT team can confirm.
Cause
This is a device configuration issue. The browser detects the certificates that Intune installs on the device and offers them for authentication, but those certificates are not meant for browser authentication.
Workaround 1: Cancel the prompt
When the certificate prompt appears, click Cancel or press Esc. In many cases, the document will then download. If the prompt immediately reappears and the document still can't be generated, move on to Workaround 2.
Workaround 2: Work with your IT team on the AutoSelectCertificateForUrls setting
This setting stops the certificate pop-up and lets the browser select the client certificate automatically. For Chrome and Edge, your IT team can apply the AutoSelectCertificateForUrls policy using the pattern for the DocGen server your Salesforce managed package points to:
{"pattern": "https://api.docgen.nintex.io", "filter": {}}
{"pattern": "https://apps.drawloop.com", "filter": {}}
For Safari, your IT team can search "Safari auto select certificate for website" for possible options.
