> We do not want any "client certificate" signed by this commercial big CA to > log in. What about your own/legitimate clients? Won't they be provided with a client cert signed by that CA?