Skip to content

Mutual TLS Auth

Implementing TLS Mutual Authentication

TLS mutual authentication (mTLS) enhances security by requiring both client and server to present valid certificates during the TLS handshake. This ensures end-to-end identity verification, critical for protecting internal services, APIs, and sensitive data in enterprise environments. Below is a step-by-step guide to configure mTLS using PKI-based certificates.


## Planning and Requirements

Before implementation, define: - Certificate Authority (CA): A trusted root CA to issue certificates. - Server Certificate: Issued to the server, signed by the CA. - Client Certificate: Issued to clients, signed by the CA. - Revocation Mechanisms: Configure CRLs or OCSP for certificate revocation. - Tools: OpenSSL, Nginx/Apache, or custom TLS stacks.

Example: A microservices architecture where clients (e.g., apps, services) must authenticate to access a protected API gateway.


## Generating Certificates

Use OpenSSL to create a CA, server, and client certificates. Replace example.com and client.example.com with your domain names.

1. Generate CA Key and CSR

openssl genrsa -out ca.key 2048
openssl req -new -key ca.key -out ca.csr -subj "/CN=CA Root"

2. Self-sign the CA Certificate

openssl x509 -req -in ca.csr -signkey ca.key -out ca.crt -days 365

3. Generate Server Key and CSR

openssl genrsa -out server.key 2
openssl req -new -key server.key -out server.csr -subj "/CN=example.com"

4. Sign Server Certificate

openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out server.crt -days 365

5. Generate Client Key and CSR

openssl genrsa -out client.key 2048
openssl req -new -key client.key -out client.csr -subj "/CN=client.example.com"

6. Sign Client Certificate

openssl x509 -req -in client.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out client.crt -days 365

## Configuring the Server

Configure your TLS stack (e.g., Nginx) to require client certificates.

Nginx Example (/etc/nginx/sites-available/mutual-tls.conf)

server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate /path/to/server.crt;
    ssl_certificate_key /path/to/server.key;

    ssl_client_certificate /path/to/ca.crt;
    ssl_verify_depth 2;
    ssl_verify_client on;

    location / {
        proxy_pass http://backend;
        proxy_set_header Host $host;
    }
}

Restart Nginx:

sudo systemctl restart nginx


## Configuring the Client

Clients must present their certificate during the TLS handshake.

Example: Using curl with Client Certificate

curl -k --cert client.crt --key client.key https://example.com

Example: Java Client (Spring Boot)

SSLContext sslContext = SSLContextBuilder.create()
    .loadTrustMaterial(new File("ca.crt"), "password".toCharArray())
    .build();

SSLContext.setDefault(sslContext);

## Testing and Validation

  1. Verify Server Configuration:

    openssl s_client -connect example.com:443 -showcerts
    
    Ensure the server requires client certs (Verify return code: 0).

  2. Test Client Authentication: Use curl or a tool like openssl s_client to simulate client authentication.

  3. Log Analysis: Check server logs for TLS handshake details:

    SSL: client certificate: CN=client.example.com
    


## Best Practices

  • Automate Certificate Management: Use tools like HashiCorp Vault or Keycloak to rotate and revoke certificates.
  • Enforce Strict Validation: Set ssl_verify_depth and reject untrusted chains.
  • Monitor Revocation: Regularly check CRLs or OCSP responders.
  • Secure Key Storage: Use hardware security modules (HSMs) for private keys.

Key takeaways

  • Plan thoroughly: Define certificate lifecycles, revocation mechanisms, and tooling.
  • Validate both sides: Ensure servers and clients enforce mutual certificate verification.
  • Automate: Integrate with IAM systems (Keycloak) or secret managers (Vault) for scalable certificate management.
  • Test rigorously: Use tools like curl or custom clients to validate TLS handshakes.
  • Monitor and rotate: Regularly audit certificates and update keys to mitigate risks.