Is it possible to configure NGINX in a way that accepts self-signed as well as CA-issued client certificates, with the CA-issued receiving proper validation and indicating t