Application Load Balancer can authenticate X.509 certificate based identities with Mutual TLS support
Share
Services
Application Load Balancer (ALB) now supports Mutual TLS enabling you to authenticate clients while establishing TLS encrypted connections.
Mutual TLS for ALB provides two different options for validating your X.509 client certificates. Using ALB’s Mutual TLS passthrough mode, ALB will send the entire client certificate chain to the target using HTTP headers, enabling you to implement relevant authentication and authorization logic in your application. Alternatively, if you are using Mutual TLS verify mode, you can offload the X.509 client certificate authentication to the ALB when negotiating TLS connections. You can authenticate clients from any third-party Certificate Authority (CA) or the [AWS Private Certificate Authority (PCA)](https://aws.amazon.com/private-ca/). You also can optionally enable revocation checks to restrict access for compromised client certificates.
You can get started by configuring Mutual TLS on ALB using AWS APIs or the AWS Management Console. For passthrough mode, you can simply configure the listener to accept any certificate(s) from the client. For verify mode, you will need to create a new Trust Store (TS) resource, upload your CA bundle and revocation lists, and attach the TS to your listener that is configured to verify client certificates.
Mutual TLS is available for ALBs in [all commercial AWS Regions](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/) and the [AWS GovCloud (US) Regions](https://aws.amazon.com/govcloud-us/). To learn more, refer to [AWS News Blog](https://aws.amazon.com/blogs/aws/mutual-authentication-for-application-load-balancer-to-reliably-verify-certificate-based-client-identities/), and the [ALB documentation](https://docs.aws.amazon.com/elasticloadbalancing/latest/application/mutual-authentication.html). For details on pricing, explore the [pricing page](https://aws.amazon.com/elasticloadbalancing/pricing/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share