client-auth doc: Document the next steps for client auth mgmt.
This based on our previous discussions from #1028, #1027, #696 (closed).
It presents a simplified version of what is proposed in #1028, and an implementation plan (in the form of action items and tickets).
This might be a bit controversial, because I'm suggesting we don't implement the JSON format from #1028