ssl_client_certificate /srv/PKI/shared/ca.pem; ssl_trusted_certificate /srv/PKI/shared/ca.pem; ssl_verify_client optional;