Trust goes both ways: Amazon CloudFront now supports viewer mTLS
Networking & Content Delivery Blog
This article announces Amazon CloudFront's support for viewer mTLS authentication, enabling bidirectional certificate-based authentication between clients and CloudFront edge locations.
- mTLS adds two-way authentication requiring both client and server certificate verification
- Supports Required mode (all clients must present valid certificates) and Optional mode (mixed authentication)
- Integrates with CloudFront Trust Store using AWS Private CA or custom certificate authorities
- Extracts client certificate information into HTTP headers for origin servers and edge functions
- Connection functions enable custom validation logic during TLS handshake with certificate revocation checking
- CloudFront connection logs track successful connections, failed handshakes, and custom log data
- Supports certificate chains up to 4 levels deep for hierarchical CA structures
- Key use cases: financial services, IoT devices, enterprise applications, healthcare, telecommunications
CloudFront viewer mTLS enables enterprises to enforce granular client authentication globally at the edge, supporting compliance requirements across regulated industries without adding latency.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.