DevNet Associate (DEVASC) v1.0Application Deployment and SecurityHard

A client application needs to interact with a secure backend API that is hosted within a Kubernetes cluster. The API requires mutual TLS (mTLS) for all incoming connections to ensure both the client and server authenticate each other. Which of the following is the correct sequence of TLS handshake steps that establishes this mutual authentication?

  1. AClient sends ClientHello -> Server sends ServerHello -> Server sends Certificate -> Server requests Client Certificate -> Client sends Certificate -> Client sends CertificateVerify -> ClientKeyExchange -> Server sends ChangeCipherSpec.
  2. BClient sends ClientHello -> Server sends ServerHello -> Server sends Certificate -> Client sends ClientKeyExchange -> Client sends Certificate -> Server sends CertificateVerify -> Server sends ChangeCipherSpec.
  3. CClient sends ClientHello -> Server sends ServerHello -> Server sends Certificate -> Client sends ClientKeyExchange -> Server sends ChangeCipherSpec.
  4. DClient sends ClientHello -> Server sends ServerHello -> Client sends Certificate -> Server sends ClientKeyExchange -> Client sends ChangeCipherSpec.
Show answer & explanation

Correct answer: A. Client sends ClientHello -> Server sends ServerHello -> Server sends Certificate -> Server requests Client Certificate -> Client sends Certificate -> Client sends CertificateVerify -> ClientKeyExchange -> Server sends ChangeCipherSpec.

In mTLS, both client and server present and verify each other's certificates. The key difference from one-way TLS is the 'Server requests Client Certificate' and 'Client sends Certificate' and 'Client sends CertificateVerify' steps, which occur after the server presents its own certificate and before the key exchange, ensuring mutual authentication.

Why the other options are wrong

  • B. The client sends its certificate and certificate verify after its ClientKeyExchange, which is out of order; the client certificate is presented before key exchange in mTLS.
  • C. This describes a standard one-way TLS handshake where only the server is authenticated.
  • D. This sequence is incorrect as the client sending its certificate before the server does, and other steps are out of order for a standard mTLS flow.

Mutual TLS (mTLS) Handshake

Mutual TLS (mTLS) is a security protocol where both the client and server authenticate each other using X.509 digital certificates during the TLS handshake.

  • Both client and server present certificates.
  • Ensures mutual authentication.
  • Adds 'Certificate Request' and 'Client Certificate' steps to standard TLS.
  • Provides strong identity verification for microservices.

Memory trick: Both sides say 'Hello', then exchange IDs, then verify, then keys.

More Application Deployment and Security questions