If you need the File Transfer Protocol (FTP) server to authenticate clients, you can change the application specifications in IBM® Digital Certificate Manager (DCM). This step is optional.
If an FTP client connects and client authentication is enabled for the server, the client must still send a USER subcommand. After the USER subcommand information is sent, the FTP server will check that the user matches the profile associated with the client certificate that the client sent to the server as part of the SSL handshake. If the user matches the client certificate, no password is needed and the FTP server will log the user onto the system. The USER subcommand is needed because there is no mechanism in the FTP protocol to "inform" the client that it's logged on without the command.