Even though there's lots of info out there around ELMAH, Thomas Ardal (founder of elmah.io) believes there's room for some extended documentation. In his words, this post is his attempt to demystify ELMAH security.
Securing REST APIs with server-side certificates is a best practice. But what if you want to take security to the next level and require client certificates?