Hello Nirav,
For SSO via SSL+CLientAuthentication, one needs digitalSignature. What you do not need here is nonRepudiation.
SSL client certificates often have also an enhanced key usage of type ClientAuthentication.
Certificates for document signing should have only nonRepudiation. They should not have ClientAuthentication.
Hope that helps :-) .
Best regards
André