What is recommended: Use UCS CA to manage client certificates, or setup a separated PKI?

maybe that helps:

rg
Christian