I am wondering if anyone has considered implementing client certificate
authentication using pkcs#11 certificates from a smartcard as well as
from file as is the case at present? Perhaps levaraging the opensc-java
project (www.opensc-project.org/opensc-java/) would help?