I use MWS with HTTPS listener and NTLM Auth, since it’s a internal server not exposed to the cloud, and I do not use client certs.
When configuring a IS listener you can configure listener port to require client certificates.
However on MWS you assign certificates to users, but for those you did not assign a cert they might be able to log in with user/password, since default auth is Forms.
Maybe create a support request and ask how-to require client certificates, and post the answer!
it might be innteresting to know.
#webMethods-BPMS#webMethods#MWS-CAF-Task-Engine