Bring your own client certificate for backend mTLS in Amazon API Gateway
Compute Blog
This article announces the ability to bring your own client certificate for backend mutual TLS (mTLS) authentication in Amazon API Gateway, enabling secure connections to backends requiring specific certificate authorities.
- Configure ACM client certificate ARN at API Gateway REST API stage for outbound mTLS handshake
- Support for third-party certificates imported to ACM or certificates from AWS Private Certificate Authority
- Solves legacy gateway migration and internal PKI mandate scenarios where backends reject self-signed certificates
- Solution demonstrates outbound mTLS between API Gateway and ECS Fargate backend with NGINX sidecar
- Automatic certificate renewal with no downtime when certificates change in ACM
- Includes step-by-step deployment guide with negative and positive testing scenarios
Enterprises can now authenticate to backends enforcing specific corporate or partner certificate authorities without relying on self-signed certificates.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2024
2025
2025
2024
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.