Website Security & Threat Management
Bring your own CA for client certificate validation with API Shield

Bring your own CA for client certificate validation with API Shield

7/11/2023 · Dina Kozlov

What this post added

This post introduces the capability for customers to bring their own Certificate Authority (CA) to use for mutual TLS (mTLS) client authentication within Cloudflare's API Shield solution. Previously, API Shield provided a self-signed CA for customers. This new feature allows customers to use their existing private CAs or CAs issued by approved third parties, enhancing security and control over their mTLS configurations. It involves uploading CAs to an account-level endpoint and associating them with mTLS-enabled hostnames via the API Shield hostname association API. The feature also includes a logging mechanism for firewall rules to test setup before enforcement.

Read the original post ↗