Mtls Configuration

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.

AI 生成的概览

指导实现用于零信任服务间通信的双向 TLS,涵盖证书、轮换与握手调试。

功能
该技能提供配置双向 TLS(mTLS)以实现零信任服务间通信的指导。它讲解 mTLS 握手流程、包含根 CA 与中间 CA 的证书层级,以及证书轮换、到期监控和 TLS 错误日志记录的最佳实践。它指向一个包含模板和详细示例的参考文件。
适用场景
适用于实施零信任网络、保护内部服务间通信、管理或轮换证书、调试 TLS 握手问题,或满足 PCI-DSS、HIPAA 等合规要求时。
运行要求
无脚本,仅为说明文档。需要阅读随附的参考文件 references/details.md 以获取模板和详细示例。

mTLS Configuration

Comprehensive guide to implementing mutual TLS for zero-trust service mesh communication.

When to Use This Skill

  • Implementing zero-trust networking
  • Securing service-to-service communication
  • Certificate rotation and management
  • Debugging TLS handshake issues
  • Compliance requirements (PCI-DSS, HIPAA)
  • Multi-cluster secure communication

Core Concepts

1. mTLS Flow

┌─────────┐                              ┌─────────┐│ Service │                              │ Service ││    A    │                              │    B    │└────┬────┘                              └────┬────┘     │                                        │┌────┴────┐      TLS Handshake          ┌────┴────┐│  Proxy  │◄───────────────────────────►│  Proxy  ││(Sidecar)│  1. ClientHello             │(Sidecar)││         │  2. ServerHello + Cert      │         ││         │  3. Client Cert             │         ││         │  4. Verify Both Certs       │         ││         │  5. Encrypted Channel       │         │└─────────┘                              └─────────┘

2. Certificate Hierarchy

Root CA (Self-signed, long-lived)    │    ├── Intermediate CA (Cluster-level)    │       │    │       ├── Workload Cert (Service A)    │       └── Workload Cert (Service B)    │    └── Intermediate CA (Multi-cluster)            │            └── Cross-cluster certs

Templates and detailed worked examples

Full template library and detailed worked examples live in references/details.md. Read that file when you need the concrete templates.

Best Practices

Do's

  • Start with PERMISSIVE - Migrate gradually to STRICT
  • Monitor certificate expiry - Set up alerts
  • Use short-lived certs - 24h or less for workloads
  • Rotate CA periodically - Plan for CA rotation
  • Log TLS errors - For debugging and audit

Don'ts

  • Don't disable mTLS - For convenience in production
  • Don't ignore cert expiry - Automate rotation
  • Don't use self-signed certs - Use proper CA hierarchy
  • Don't skip verification - Verify the full chain

来源与署名

来源:wshobson/agents位于plugins/cloud-infrastructure/skills/mtls-configuration提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架