When MTLS is enabled on level Trusted, client certificate is requested
and verified in every SSL/TLS handshake (in initial handshake and also
in every succeeding renegotiation).
Last certificate in certificate chain supplied by the client must
be signed by one of trusted CA and must not be expired, otherwise handshake
fails immediately and connection is terminated.
Incorrect X509v3 extensions and unknown critical X509v3 extensions
are not ignored on level Trusted due to underlying framework (even though
they should be).