Agreed with above comment. However the question is then how to set up service to authenticate clients using certificate when Transport security is used? I want to ensure what my service is only called by certain clients. Do I have to do this via Message security?