TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan
Amankan panggilan antar layanan gRPC dengan TLS saling autentikasi, saat klien dan server sama-sama menyajikan sertifikat untuk membuktikan identitas secara kriptografis.
TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan adalah pelajaran gRPC & High Performance APIs gratis di CoddyKit. Ini adalah pelajaran 4 dari 4. Kamu bisa membaca pelajaran lengkapnya di bawah secara gratis — lalu praktikkan langsung di browser dengan editor kode bawaan dan tutor AI 24/7. Ini adalah bagian dari jalur belajar gRPC & High Performance APIs, dan progresmu tersinkronisasi di web dan aplikasi CoddyKit. Kursus gRPC & High Performance APIs mencakup 4 pelajaran total.
Bagian dari pelajaran ini belum diterjemahkan dan ditampilkan dalam bahasa Inggris.
Beyond One-Way TLS
Standard TLS authenticates only the server to the client. In a zero-trust network, the server also needs to verify who is calling.
Mutual TLS (mTLS) makes both sides present certificates.
How mTLS Works
During the handshake:
- The server sends its certificate (as in normal TLS)
- The server then requests the client's certificate
- The client presents its cert and proves it holds the private key
- Each side validates the other against a trusted CA
The Role of the CA
A Certificate Authority (CA) signs both client and server certs. Each peer trusts the CA, so any cert signed by it is accepted. In service meshes an internal CA issues short-lived certs automatically.
Generating Certificates
For a test setup you create a CA, then sign a server cert and a client cert with it. Tools like openssl or cfssl produce the key/cert pairs.
openssl req -x509 -newkey rsa:4096 -keyout ca.key -out ca.crt -days 365 -nodesServer Side in Go
Configure the server's tls.Config to load its cert and require client certs verified against the CA pool.
cfg := &tls.Config{
Certificates: []tls.Certificate{serverCert},
ClientCAs: caPool,
ClientAuth: tls.RequireAndVerifyClientCert,
}
creds := credentials.NewTLS(cfg)Wiring the Server
Pass the TLS credentials when constructing the gRPC server so every connection is mutually authenticated.
s := grpc.NewServer(grpc.Creds(creds))Client Side in Go
The client presents its own certificate and trusts the CA to validate the server.
cfg := &tls.Config{
Certificates: []tls.Certificate{clientCert},
RootCAs: caPool,
}
conn, _ := grpc.Dial(addr, grpc.WithTransportCredentials(credentials.NewTLS(cfg)))Reading the Peer Identity
Once connected, the server can read the client's certificate from the connection's peer info and use the subject or SAN as an authenticated identity.
p, _ := peer.FromContext(ctx)
tlsInfo := p.AuthInfo.(credentials.TLSInfo)
name := tlsInfo.State.PeerCertificates[0].Subject.CommonNameCertificate Rotation
Certs expire. Production systems rotate them frequently using short lifetimes (hours/days). A sidecar or mesh control plane reloads new certs without restarting the service.
mTLS in Service Meshes
Meshes like Istio or Linkerd automate mTLS entirely: sidecar proxies handle the handshake, issue certs, and rotate them, so application code stays unchanged.
Common Pitfalls
Watch out for:
- Clock skew breaking cert validity checks
- Wrong CA pool causing handshake failures
- Mismatched SAN/hostname errors
- Forgetting
RequireAndVerifyClientCert(downgrades to one-way TLS)
Quick Check
Test your mTLS understanding.
Recap
You learned mutual TLS for gRPC:
- mTLS authenticates both client and server
- A shared CA signs and validates certificates
- Set
RequireAndVerifyClientCerton the server, present a client cert on the dial - Read peer identity from the verified certificate
- Rotate certs often; meshes automate the whole flow
Belajar gRPC & High Performance APIs dengan tutor AI — gratis
Tulis dan jalankan kode asli di browser kamu, dapatkan bantuan instan dari tutor AI 24/7, dan lanjutkan di mana kamu tinggalkan di web atau aplikasi.
- Kursus
- 12
- Pelajaran
- 48
Pertanyaan yang Sering Diajukan
Apakah pelajaran “TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan” gratis?
Ya — teks lengkap “TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan” gratis dibaca di sini di web. Untuk praktiknya secara interaktif (editor kode bawaan dan tutor AI 24/7) dan buka sisa kursus gRPC & High Performance APIs, upgrade ke CoddyKit PRO. Kursus gRPC & High Performance APIs mencakup 4 pelajaran total.
Apa yang akan aku pelajari di “TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan”?
Amankan panggilan antar layanan gRPC dengan TLS saling autentikasi, saat klien dan server sama-sama menyajikan sertifikat untuk membuktikan identitas secara kriptografis. Kamu berlatih gRPC & High Performance APIs dengan kode praktik yang langsung kamu jalankan di browser, dan tutor AI 24/7 menjawab pertanyaanmu saat kamu mengerjakan pelajaran ini.
Apakah aku perlu pengalaman untuk memulai gRPC & High Performance APIs?
Tidak diperlukan pengalaman sebelumnya. gRPC & High Performance APIs di CoddyKit dirancang untuk pemula hingga pelajar tingkat lanjut, jadi kamu bisa memulai di sini atau dari awal dan belajar sesuai kecepatan kamu sendiri. Ini adalah pelajaran 4 dari 4.
Berapa lama pelajaran “TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan” memakan waktu?
Sebagian besar pelajaran CoddyKit memakan waktu sekitar 5–10 menit. Setiap pelajaran ringkas dan interaktif, jadi kamu membuat kemajuan stabil dan melanjutkan dari tempat kamu tinggalkan di web dan aplikasi.
Bisakah aku menulis dan menjalankan kode dalam pelajaran gRPC & High Performance APIs ini?
Ya. Setiap pelajaran gRPC & High Performance APIs menyertakan editor kode bawaan, jadi kamu menulis dan menjalankan kode nyata langsung di browser dan mendapatkan umpan balik AI instan — tidak diperlukan penyiapan lokal.
Semua pelajaran dalam kursus ini
- TLS/SSL untuk gRPC
- Autentikasi dan Otorisasi
- Interceptor untuk Keamanan
- TLS Saling Autentikasi (mTLS) untuk Autentikasi Layanan