How to optionally request a client certificate?

From: Michael Schmidt <>
Date: Sat, 19 Feb 2011 01:02:28 +0100

How can I optionally request client certificate authentication - i.e., enable clients to show their certificate if they have one, and still proceed if they don't have a client certificate installed?

The Blog [1] reads to add a property to http-listener element in domain.xml:
<property name="com.sun.grizzly.ssl.auth" value="want"/>

However, the existing browser client certificate is not requested. The GlassFish server is properly set up, i.e., requires client certificates with the option "client-auth-enabled" set to true.

A different version described at [2] doesn't work either.

Any ideas on this?


