Overview
Mutual TLS (mTLS) provides strong, certificate-based authentication by requiring both parties in a TLS connection to verify each other’s identity. Within the context of Threat Protection, mTLS helps enforce a zero-trust architecture by ensuring only trusted clients and servers can exchange traffic.
Supported mTLS Flows
Threat Protection supports mTLS in two directions:
-
Client to Proxy (Downstream) Clients must present a valid certificate before traffic is allowed.
-
Proxy to Server (Upstream) The proxy authenticates itself to your backend server and optionally validates the backend’s identity.
Prerequisites
Before configuring mTLS, ensure:
- mTLS is enabled on your account
- You have the required CA and identity certificates
Note: mTLS must be enabled on your account by Threat Protection support. Contact the support team on support@baffinbay.com to enable this feature.