This fixes Issue https://github.com/arthepsy/pan-globalprotect-okta/issues/17 raised by @lvml.
(Note that if you need to specify a client certificate for the `vpn_url`, then most probably
you will also need to give the same certificate to the final `openconnect` call with `--certificate` via the `openconnect_args`)