mTLS

Turkish equivalent: Karşılıklı TLSDomain: Cybersecurity

Mutual TLS authentication in which both endpoints present and validate certificates rather than authenticating only the server.

Mutual TLS (mTLS) is a TLS authentication model in which both the server and the client authenticate with certificates.

mTLS — Mutual TLS authentication in which both endpoints present and validate certificates rather than authenticating only the server.

Security Context

Mutual TLS authenticates both sides of a TLS connection by having each endpoint validate an X.509 certificate chain. In service-to-service deployments, private certificate authorities, issuance, rotation, revocation, and key protection become part of the operational security design.

Authorization Boundary

mTLS establishes an authenticated cryptographic peer and encrypts the channel, but a valid certificate does not automatically grant access to an application resource. Authorization remains a separate policy decision.

Authentication Is Not Authorization

The current TLS 1.3 specification is RFC 9846, published in July 2026 and superseding RFC 8446. In TLS 1.3, server authentication is part of the core protocol flow while client authentication is optional. In practical usage, mTLS refers to a channel in which certificate-based authentication is used for both peers.

This distinction is critical in Zero Trust designs: a valid certificate contributes evidence that a peer has a particular cryptographic identity, but it does not decide whether that peer may read or modify an application resource. Authorization still evaluates service identity, role, scope, tenant, or other policy context. Certificate lifecycle is also broader than the handshake itself; private CAs, key protection, rotation, and revocation belong to the operational security contract. Protocol basis: RFC 9846.