Amazon CloudFront now supports passthrough mode for viewer mutual TLS (mTLS) authentication. Unlike the existing required and optional modes that offload certificate verification to CloudFront using trust stores, passthrough mode forwards the full client certificate chain directly to the origin for validation. This allows organizations with existing mTLS infrastructure to use CloudFront without reconfiguring their validation logic at the edge. Caching is disabled in this mode to ensure end-to-end authentication per request, and Connection functions remain available for inspecting or transforming certificate data before it reaches the origin. The feature is available at no additional cost.

1m read timeFrom aws.amazon.com
Post cover image
277 Impressions