After spending a few days on this I found out that:
- When using X509 certs in "user authentication", Tiger will do PSK instead of RSA
- I cannot find a way to import a valid certificate (in pkcs11/pkcs7/pem.crt) format so that the certificate becomes avalable for "machine authentication"...