Service identity & mTLS

P58.service-to-service.01 · Audience: guest, it-ml, language-pro · Prerequisites: The TLS 1.3 handshake, Zero trust: never trust the network

Real LLM grading for this pageLLM grading (this page):

Ordinary TLS (P53) proves the server's identity to the client. Between services that is only half of what you need: the server must also know which workload is calling. With one-sided authentication, any client that can reach the service — a compromised pod, a stray script — is accepted at the transport layer.

mTLS closes it: both sides present a certificate, both validate the other's, and only then is a session established. This module builds that state machine, deriving the session key with HMAC (ties P52) once — and only once — both sides have proven themselves.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — mutual TLS: both sides prove it

Loading exercise…

My notes on this module

Loading your notes...

Service identity & mTLS — TransformerLab