simonwjudell Thanks. I'm managing cert based auth between some systems at work. I like the fact that it doesn't involve userids and passwords. I like the fact that I can generate short-lived certificates. But it sure is fiddly! I was wondering how it might work "in public."