@sindarina I have been following this approach (of making ClientAuth less and less desired and actively being fought) since many years, going back to the times of https://unhosted.org where client certificate based auth was an actual browser feature we hoped to use for decentralised architectures. This is just another step to making such architectures far more complex and effectively unusable. THAT's what I oppose.