Home icon

Amazon CloudFront now supports mTLS authentication to origins

Networking & Content Delivery Blog



This article announces that Amazon CloudFront now supports mutual TLS (mTLS) authentication between CloudFront and customer origins, enabling end-to-end encrypted and authenticated connections.

  • CloudFront extends mTLS from viewers to origins for complete authentication path
  • Enables zero-trust architecture by removing implicit trust between tiers
  • Supports client certificates from AWS Private CA or third-party CAs
  • Per-origin configuration allows different certificates for different backends
  • Prerequisites include X.509v3 client certificate and origin server mTLS support
  • Connection overhead limited to handshake phase; steady-state performance unaffected
  • AWS Private CA recommended for automated lifecycle and renewal management

CloudFront-to-origin mTLS closes trust gaps in edge architectures, providing cryptographic identity verification across the entire request path for regulated and high-risk workloads.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 2
2026
Amazon CloudFront announces mutual TLS support for origins
Nov 24
2025
Amazon CloudFront announces support for mutual TLS authentication
Nov 24
2025
Trust goes both ways: Amazon CloudFront now supports viewer mTLS
Nov 20
2025
Amazon CloudFront now supports TLS 1.3 for origin connections

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.