Amazon CloudFront announces support for mutual TLS Authentication (mTLS), a security protocol that requires both the server and client to authenticate each other using X.509 certificates, enabling customers to validate client identities at CloudFront’s edge locations. Customers can now ensure only clients presenting trusted certificates can access their distributions, helping protect against unauthorized access and security threats.
Previously, customers had to spend ongoing effort implementing and maintaining their own client access management solutions, leading to undifferentiated heavy lifting. Now with the support for mutual TLS, customers can easily validate client identities at the AWS edge before connections are established with their application servers or APIs. Example use cases include B2B secure API integrations for enterprises and client authentication for IoT. For B2B API security, enterprises can authenticate API requests from trusted third parties and partners using mutual TLS. For IoT use cases, enterprises can validate that devices are authorized to receive proprietary content such as firmware updates. Customers can leverage their existing third-party Certificate Authorities or AWS Private Certificate Authority to sign the X.509 certificates. With Mutual TLS, customers get the performance and scale benefits of CloudFront for workloads that require client authentication.
Mutual TLS authentication is available to all CloudFront customers at no additional cost. Customers can configure mutual TLS with CloudFront using the AWS Management Console, CLI, SDK, CDK, and CloudFormation. For detailed implementation guidance and best practices, visit CloudFront Mutual TLS (viewer) documentation.
Categories: general:products/amazon-cloudfront,marketing:marchitecture/networking-and-content-delivery
Source: Amazon Web Services
Latest Posts
- Amazon CloudFront announces support for mutual TLS authentication
- Amazon EC2 announces interruptible Capacity Reservations

- Dynamics 365 Contact Center – Contact customers proactively with personalized options [MC1189618]
![Dynamics 365 Contact Center - Contact customers proactively with personalized options [MC1189618] 2 colorful liquid 7774019 1280](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Teams on the web: New Private Preview for Sign in with Apple and Google for consumers may affect enterprise [MC1102784]
![Microsoft Teams on the web: New Private Preview for Sign in with Apple and Google for consumers may affect enterprise [MC1102784] 3 pexels freestockpro 1003851](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Dynamics 365 Contact Center - Contact customers proactively with personalized options [MC1189618] 2 colorful liquid 7774019 1280](https://mwpro.co.uk/wp-content/uploads/2025/06/colorful-liquid-7774019_1280-150x150.webp)
![Microsoft Teams on the web: New Private Preview for Sign in with Apple and Google for consumers may affect enterprise [MC1102784] 3 pexels freestockpro 1003851](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-freestockpro-1003851-150x150.webp)