Collapse AllExpand All

18.8.6.1.4. Trusted Level Features Previous topic Parent topic Child topic Next topic

When MTLS is enabled on level Trusted, client certificate is requested and verified in every SSL/TLS handshake (in initial handshake and also in every succeeding renegotiation).
Last certificate in certificate chain supplied by the client must be signed by one of trusted CA and must not be expired, otherwise handshake fails immediately and connection is terminated.
Incorrect X509v3 extensions and unknown critical X509v3 extensions are not ignored on level Trusted due to underlying framework (even though they should be).