Enabling Client-to-Proxy mTLS
Client-to-Proxy mTLS ensures that users must present a valid certificate to the Threat Protection proxy before traffic is allowed through.
Steps
- Open Traffic Configuration for the relevant HTTP proxy.
- Scroll to the Mutual TLS (mTLS) section.
- Toggle mTLS Client to Proxy to On position.
- Under Configure Trust Store:
- Select one or more previously uploaded CA certificates from the dropdown menu
- Click Add
Note: You can select up to 5 CA certificates for client validation.
- Check CRL Validation status.
- Ensure CRL Validation is enabled if you require real-time revocation checking.
Result
- Only clients presenting valid certificates issued by trusted CAs are allowed access.