The following configuration forwards the client certificate as a URL-encoded PEM block in the ssl-client-cert header, matching the format produced by nginx's auth-tls-pass-certificate-to-upstream ...