Mutual TLS Auth
Implementing TLS Mutual Authentication¶
TLS mutual authentication (mTLS) enhances security by requiring both client and server to present valid certificates during the TLS handshake. This ensures end-to-end identity verification, critical for protecting internal services, APIs, and sensitive data in enterprise environments. Below is a step-by-step guide to configure mTLS using PKI-based certificates.
## Planning and Requirements¶
Before implementation, define: - Certificate Authority (CA): A trusted root CA to issue certificates. - Server Certificate: Issued to the server, signed by the CA. - Client Certificate: Issued to clients, signed by the CA. - Revocation Mechanisms: Configure CRLs or OCSP for certificate revocation. - Tools: OpenSSL, Nginx/Apache, or custom TLS stacks.
Example: A microservices architecture where clients (e.g., apps, services) must authenticate to access a protected API gateway.
## Generating Certificates¶
Use OpenSSL to create a CA, server, and client certificates. Replace example.com and client.example.com with your domain names.
1. Generate CA Key and CSR¶
2. Self-sign the CA Certificate¶
3. Generate Server Key and CSR¶
openssl genrsa -out server.key 2
openssl req -new -key server.key -out server.csr -subj "/CN=example.com"
4. Sign Server Certificate¶
5. Generate Client Key and CSR¶
openssl genrsa -out client.key 2048
openssl req -new -key client.key -out client.csr -subj "/CN=client.example.com"
6. Sign Client Certificate¶
## Configuring the Server¶
Configure your TLS stack (e.g., Nginx) to require client certificates.
Nginx Example (/etc/nginx/sites-available/mutual-tls.conf)¶
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /path/to/server.crt;
ssl_certificate_key /path/to/server.key;
ssl_client_certificate /path/to/ca.crt;
ssl_verify_depth 2;
ssl_verify_client on;
location / {
proxy_pass http://backend;
proxy_set_header Host $host;
}
}
Restart Nginx:
## Configuring the Client¶
Clients must present their certificate during the TLS handshake.
Example: Using curl with Client Certificate¶
Example: Java Client (Spring Boot)¶
SSLContext sslContext = SSLContextBuilder.create()
.loadTrustMaterial(new File("ca.crt"), "password".toCharArray())
.build();
SSLContext.setDefault(sslContext);
## Testing and Validation¶
-
Verify Server Configuration:
Ensure the server requires client certs (Verify return code: 0). -
Test Client Authentication: Use
curlor a tool likeopenssl s_clientto simulate client authentication. -
Log Analysis: Check server logs for TLS handshake details:
## Best Practices¶
- Automate Certificate Management: Use tools like HashiCorp Vault or Keycloak to rotate and revoke certificates.
- Enforce Strict Validation: Set
ssl_verify_depthand reject untrusted chains. - Monitor Revocation: Regularly check CRLs or OCSP responders.
- Secure Key Storage: Use hardware security modules (HSMs) for private keys.
Key takeaways¶
- Plan thoroughly: Define certificate lifecycles, revocation mechanisms, and tooling.
- Validate both sides: Ensure servers and clients enforce mutual certificate verification.
- Automate: Integrate with IAM systems (Keycloak) or secret managers (Vault) for scalable certificate management.
- Test rigorously: Use tools like
curlor custom clients to validate TLS handshakes. - Monitor and rotate: Regularly audit certificates and update keys to mitigate risks.