Currently one of the threat intelligence providers gives us an API link to download the threat feeds. But they are planning to change it to the two factor authentication (username, password and certificate). Also, their URL changes everyday.
My Questions:
ES does support certificate-based authentication for TAXII feeds, as long as that is what the format is. See instructions here: http://docs.splunk.com/Documentation/ES/4.2.1/User/Configureblocklists#Add_a_TAXII_feed_with_certifi...
I can't comment on #2, but I'd presume that it's something you could work out withe some form of a modular input.