The Wayback Machine - https://web.archive.org/web/20230920152932/https://github.blog/category/engineering/

Category

Engineering

mTLS: When certificate authentication is done wrong

mTLS: When certificate authentication is done wrong

In this post, we'll deep dive into some interesting attacks on mTLS authentication. We'll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.

Michael Stepankin