Note: Because client authentication could involve prompting the user,
servers MUST be prepared for some delay, including receiving an
arbitrary number of other messages between sending the
CertificateRequest and receiving a response.
A malicious client can try to send other messages without sending authentication messages in a hope that the server crashes.