Certificate-based Authentication is often thought of as superior to Password-based Authentication, especially when backed by the Enterprise's internal Certificate Authority — but how many services actually validate whether a certificate was intended for them?