I have setup a lab on vmware with both of them. It works but it doesn't suit my business case. I would like to have windows form authentication first. If sucessfull I want to check client certificate. But even if user doesn't have client certificate he would still be able to access some pages but with some restrictions.

Unfortunately in standard config I can't do this because client certificate is prompted first and if user doesn't have client certificate he cannot access the authentication form as it is protected by same ssl.

Is it possible to configure windows to do things the other way round: 1°) forms authentication 2°) client certificate authentication ?

