Found the bug...
The CertMapping.Subject should include the actual Subject CN of the client certificate, and not the fingerprint.