Use curl for PKI realm authentication

Can you point to the docs that say that?
It's certainly not true, if it were true then every http connection would need a client certificate.

You should explicitly enable TLS client authentication. I would recommend that you set it to optional.