4 ms·
Apache APISIX also has several security features to help reinforce API security. For instance: 1. It can dynamically manage lots of TLS certificates and do the
by chao-zhang 4y ago
Apache APISIX also has several security features to help reinforce API security. For instance:
1. It can dynamically manage lots of TLS certificates and do the TLS/SSL terminate or use mTLS to communicate with the upstream;
2. Plugins like ACL, IP Restriction, CSRF, and Referrer Restriction restrict API access in different dimensions.
- adamckay 4y agoIs it possible to perform mTLS from client->APISIX gateway and pass on the verified certificate details to the upstream (e.g. via headers)? Or is mTLS only possible with client->pass through APISIX->upstream? It's not quite clear from the docs.
- chao-zhang 4y agoIt's feasible while you have to write a bit of code to assemble the certificate details to the API request (e.g., request headers, or query string). mTLS is both possible for client -> APISIX and APISIX -> upstream.
- bzp2010 4y agoAs a complement to the first reply, I created a simple DEMO that will implement your needs and I placed it on the GitHub gist [1]. [1] https://gist.github.com/bzp2010/6ce0bf7c15c191029ed54724547195b4 https://gist.github.com/bzp2010/6ce0bf7c15c191029ed547245471...