Enable mTLS (mutual TLS)
Last updated
Was this helpful?
Last updated
Was this helpful?
Link11 WAAP supports mTLS encryption. The scope of this feature is as follows:
mTLS is optional, and can be enabled for individual Server Groups.
Admins upload CA Certificates, and assign them to Server Groups (as described below).
Currently, mTLS can be enforced between clients and L11WAAP. A later release will add enforcement between L11WAAP and the origin.
In the user interface, mTLS is only available when using an (Network Load Balancer). To enable mTLS when using a Link11 load balancer, contact support.
When mTLS is enabled, the user must present a client certificate at the beginning of each session during the TLS handshake. L11WAAP will validate the date and issuer of the certificate. If validation fails, the user will receive an error, and will not be permitted to connect to the protected system.
Setting up mTLS is a straightforward process:
Upload the CA Certificate(s) in the CA Certificates tab of the page.
your changes.
Assign the appropriate certificate to each Server Group:
Open the Server Group in the page.
Turn on the CA Certificate toggle.
A dropdown list of CA Certificates will appear. Select the appropriate one.
Publish your changes.