FILTER BY TAG

Mutual TLS Two-Way Handshake

With mTLS, the authentication message exchange between client and server is called an
SSL handshake
. This sequence summarizes the components of the mTLS process handshake:
  1. Client hello
    —The client initiates a connection by sending a "Client Hello" message. The message includes supported cryptographic algorithms and the client's public key.
  2. Server hello
    —The server responds with a "Server Hello" message, including its public key and a digital certificate issued by the DigiCert trusted Certificate Authority (CA).
  3. Client certificate request
    —The server requests a certificate from the client for authentication.
  4. Client certificate
    —The client sends its certificate, which is validated by the server.
  5. Handshake completion
    —Both parties exchange keys and establish a secure, encrypted communication channel.
After the handshake completes successfully, the client and server use the
symmetric key
for encrypting and decrypting data.