In terms of validating the certificate, the relevant CA key as to be configured as trusted.
Based on the other responses in this thread, you have not done this yet.
Once you do this, you can issue certificates from your Certificate Authority.
If you want to treat some users differently in your access policy, we need some way to differentiate the users.
That either means:
- Creating each user locally with the appropriate authentication method and adding them to a group
- Using LDAP
Nothing has changed here.