> Ok, I can agree with that, although using client certificates only > doubles the amount of public-key operations that the server has to do It does? How do you figure that? Does that include verifying the signatures on the certificate chain and checking the CRLs? - Marc