On This Page
Mutual TLS Two-Way Handshake
With mTLS, the authentication message exchange between client and server is called an
SSL handshake
.
This sequence summarizes the components of the mTLS process handshake:- Client hello—The client initiates a connection by sending a "Client Hello" message. The message includes supported cryptographic algorithms and the client's public key.
- Server hello—The server responds with a "Server Hello" message, including its public key and a digital certificate issued by the DigiCert trusted Certificate Authority (CA).
- Client certificate request—The server requests a certificate from the client for authentication.
- Client certificate—The client sends its certificate, which is validated by the server.
- Handshake completion—Both parties exchange keys and establish a secure, encrypted communication channel.
After the handshake completes successfully,
the client and server use the
symmetric key
for encrypting and decrypting data.