Home icon

Trust goes both ways: Amazon CloudFront now supports viewer mTLS

Networking & Content Delivery Blog



This article announces Amazon CloudFront's support for viewer mTLS authentication, enabling bidirectional certificate-based authentication between clients and CloudFront edge locations.

  • mTLS adds two-way authentication requiring both client and server certificate verification
  • Supports Required mode (all clients must present valid certificates) and Optional mode (mixed authentication)
  • Integrates with CloudFront Trust Store using AWS Private CA or custom certificate authorities
  • Extracts client certificate information into HTTP headers for origin servers and edge functions
  • Connection functions enable custom validation logic during TLS handshake with certificate revocation checking
  • CloudFront connection logs track successful connections, failed handshakes, and custom log data
  • Supports certificate chains up to 4 levels deep for hierarchical CA structures
  • Key use cases: financial services, IoT devices, enterprise applications, healthcare, telecommunications

CloudFront viewer mTLS enables enterprises to enforce granular client authentication globally at the edge, supporting compliance requirements across regulated industries without adding latency.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 2
2026
Amazon CloudFront now supports mTLS authentication to origins
Nov 24
2025
Amazon CloudFront announces support for mutual TLS authentication
May 14
2026
Amazon CloudFront announces Passthrough Mode for mutual TLS (Viewer)
Sep 9
2025
Amazon CloudFront adds ECDSA support for signed URLs

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.