The Wayback Machine - https://web.archive.org/web/20230927033154/https://github.blog/category/security/

Category

Security

mTLS: When certificate authentication is done wrong

mTLS: When certificate authentication is done wrong

In this post, we'll deep dive into some interesting attacks on mTLS authentication. We'll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.

Michael Stepankin