Thanks Michael, that makes sense! We are fronting all calls with an apache configured to perform the mutual TLS, but despite sending the client cert info forward (or so I thought), the cert prompt never showed. Having said that, there could easily have been some misconfiguration between the fronting apache, the nginx reverse proxy, or the backend jetty server. Plenty of opportunities to drop that cert information. :)