The client verfies the server according to it's certificate, that certificate is issued by a trusted certificate authority. By using X.509 in Spring Security the server verifies the identity of the ...