Thanks for this. I have just recently been messing with this kind of setup. The TLS method and forcing it to use that key instead of just the username and password is much more secure. However I still can't help wanting to set up a separate, unique client cert key for each user/device.
It...