I am aware that Confluence / Crowd does not currently directly support Client Certificate-based authentication to Confluence via PKI, per this discussion. As any such support remains a distant and uncertain prospect, I am wondering whether there are alternate, more convoluted means to achieve the same result.
Specifically, is there a way to use client certificates to authenticate to an (Open) LDAP service, and then have the service broker authentication to Confluence over Crowd (which seems to support LDAP), with client certificates being used for the entire process from the perspective of user (i.e. user is never prompted for/enters a password directly)?