HTTP 496 – SSL Certificate Required
(NGINX) The client did not present the SSL certificate required by the server during mutual TLS authentication.
Common use case
Returned when an mTLS-protected endpoint expects a client certificate and the client simply doesn't send one at all.
History
An NGINX-specific extension, the sibling code to 495 for the "no certificate at all" case.
Did you know?
The distinction between this and 495 (invalid certificate vs. missing certificate) helps operators quickly tell misconfiguration apart from a genuine attack attempt.