Mutual TLS (mTLS)
Set up mutual TLS for Bindplane collector receivers with two-way authentication.
What is Mutual TLS?
Standard TLS vs Mutual TLS
Benefits of Mutual TLS
When to Use Mutual TLS
mTLS Configuration Options
Option 1: ca_file (Opportunistic Client Verification)
ca_file (Opportunistic Client Verification)Option 2: client_ca_file (Required Client Verification)
client_ca_file (Required Client Verification)Comparison Table
Setting Up mTLS Certificates
Server Side (Collector)
Client Side
PKI Infrastructure Considerations
Complete mTLS Configuration Examples
TCP Receiver with mTLS
Syslog Receiver with mTLS
Production mTLS with Security Hardening
Configuring mTLS in the Bindplane UI
Step-by-Step UI Configuration
UI Field Mapping
Bindplane UI Field
YAML Parameter
Purpose
Testing mTLS Connections
Test with Valid Client Certificate
Test Rejection of Unauthorized Clients
Verify Client Certificate Details
mTLS Troubleshooting
Issue: Client Certificate Required Errors
Issue: Client Certificate Verification Fails
Issue: Connections Accepted Without Client Certificates
Issue: Client CA Changes Not Taking Effect
Last updated
Was this helpful?