Hello Piyush,
I'm not sure why the Reverse Proxy is not allowing you to perform OAuth authentication when certificates are enabled. I will try to find out.
In the meantime, the "prompt-as-needed" setting means that when authentication is required, a form-based login page will be displayed which has an option on it to trigger certificate authentication by clicking a button. If you are using a custom login page perhaps you no longer have that component on your login page.
It's worth saying that "prompt-as-needed" authentication is not as simple as it used to be because some browsers (Chrome for sure) no longer allow a TLS session to be re-negotiated once it has started. To work-around this there's an option to switch out to an alternative port to perform the certificate authentication. This requires some additional configuration work. See the note on this page:
https://www.ibm.com/support/knowledgecenter/SSPREK_10.0.0/com.ibm.isva.doc/wrp_config/task/tsk_enbl_cert_authe.htmI hope this helps.
Jon.
------------------------------
Jon Harry
Consulting IT Security Specialist
IBM
------------------------------