Alert
Amazon CloudFront announces Passthrough Mode for mutual TLS Viewer
Amazon CloudFront now supports passthrough mode for mutual TLS mTLS viewer authentication, allowing CloudFront to forward client certificates to the origin
Alert
Amazon CloudFront now supports passthrough mode for mutual TLS mTLS viewer authentication, allowing CloudFront to forward client certificates to the origin
Amazon CloudFront now supports passthrough mode for mutual TLS (mTLS) viewer authentication, allowing CloudFront to forward client certificates to the origin without verifying the certificates on CloudFront. Customers who already validate client certificates at their origin can now add CloudFront to their existing mTLS infrastructure without changing how or where validation happens.
In passthrough mode, customers configure mutual TLS on their CloudFront distribution without setting up a trust store. CloudFront forwards every request along with the client's full certificate chain directly to the origin for authentication. Connection functions, which allow customers to inspect or transform connection-level data at the edge, still run on every request, enabling customers to process or reformat certificate headers before requests reach the origin. Customers benefit from CloudFront's global edge network while maintaining their current mutual TLS authentication architecture.
Passthrough mode is now available alongside other mutual TLS modes in CloudFront. Required mode validates all client certificates against trust stores at the edge. Optional mode allows customers to configure trust store validation at the edge while serving both clients that present certificates and clients that do not present certificates from the same application. CloudFront mutual TLS in passthrough mode is available at no additional cost. To learn more, refer to the documentation for CloudFront Mutual TLS (Viewer).
Today, Amazon GameLift Streams launched Generation 6e G6e stream classes, providing enhanced GPU performance for streaming high-fidelity, graphically demanding games and applications. The new G6e stream classes are pow…
Amazon SageMaker Unified Studio IAM domains now includes an interactive interface for creating and managing feature groups in SageMaker Feature Store, eliminating the need to write code for common feature management task…
Over the last 25 years of building Google’s global network, we’ve navigated major architectural eras — from the Internet, to streaming, and the cloud. Today, we are squarely in the midst of a fourth: the AI era. The appl…