3 ms·
Cloudflare allows you to enable mTLS for websites: https://developers.cloudflare.com/ssl/client-certificates/enable-mtls https://developers.cloudflare.com/ssl/
by ArchOversight 3y ago
Cloudflare allows you to enable mTLS for websites:
https://developers.cloudflare.com/ssl/client-certificates/enable-mtls https://developers.cloudflare.com/ssl/client-certificates/en...
https://developers.cloudflare.com/cloudflare-one/identity/devices/access-integrations/mutual-tls-authentication/ https://developers.cloudflare.com/cloudflare-one/identity/de...
This would then require Cloudflare to request a client certificate. This is great for securing websites using corporate identity that is derived from AD certs for example to make sure the device being used has a valid cert on it.
Alongside MDM for example forcing the certificate to have a short lifespan (my $CORP uses 7 days) you can validate that the device has the correct security posture to access the resources.
If for example I let my device not update the version of macOS often enough my cert expires and I can't access internal resources until I update my OS and MDM software checks that and provisions me a new device certificate.