How keycloak 16.1.1 config one way tls?

i get the certificate using this script openssl s_client -connect 192.68.1.13:636 -showcerts < /dev/null

im using keycloak version 16.1.1 my question is how to configure one way TLS in keycloak?

here is my docker compose and my certificate file is tls.pem

services:
  identity-service:
        image: quay.io/keycloak/keycloak:16.1.1
        container_name: ad_con
        command: -c standalone.xml
        environment:
            - KEYCLOAK_USER=admin
            - KEYCLOAK_PASSWORD=admin
            - KEYCLOAK_IMPORT=/tmp/alfresco-realm.json
            - DB_VENDOR=h2	
        volumes:
            - ./cert/tls.pem:/cert/tls.pem
        
        ports:
            - 9999:8080
            - 9443:8443