Support explicit direct-mTLS and trusted-reverse-proxy authentication
modes with mutually authenticated backend transport.
Keep proxy and end-client principals separate, validate forwarded
certificates independently, and enforce narrowly scoped forwarding
authority for RFC 9440 and NGINX escaped-PEM profiles.