The server stores the public cert from all clients and uses it to authenticate at the transport layer. No shared secrets either.