When using this authentication method, the server will require that
the client provide a certificate. No password prompt will be sent
to the client. The <literal>cn</literal> attribute of the certificate
- will be matched with the username the user is trying to log in as,
- and if they match the login will be allowed. Username mapping can be
- used if the usernames don't match.
+ will be matched with the login username, and if they match the
+ login will be allowed. Username mapping can be used if the usernames
+ don't match.
</para>
</sect2>