# Possible to reverse proxy to mTLS authenticated backend?

**URL:** <https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579>\
**Category:** help\
**Created:** [August 3, 2017, 8:18pm UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579 "2017-08-03T20:18:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![nwwells](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/nwwells/32/182_2.png) [@nwwells](https://discourse.mitmproxy.org/u/nwwells)\
**Post date:** [August 3, 2017, 8:18pm UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/1 "2017-08-03T20:18:09Z")

</div>

Hi! This seems like a really cool project. Thanks for all the hard work. I was wondering if it was possible to have `mitmproxy` do a reverse proxy to a remote mTLS authenticated host? I have a cert and key to be used for authentication, and I want to expose an endpoint on my localhost that does _not_ require mTLS.

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [August 4, 2017, 2:04am UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/2 "2017-08-04T02:04:21Z")

</div>

Hi @nwwells,

What is “mTLS”? Are you referring to [https://tools.ietf.org/html/draft-badra-hajjeh-mtls-06](https://tools.ietf.org/html/draft-badra-hajjeh-mtls-06) or just mutually authenticated TLS?

---

<div class="post-metadata">

**Author:** ![nwwells](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/nwwells/32/182_2.png) [@nwwells](https://discourse.mitmproxy.org/u/nwwells)\
**Post date:** [August 4, 2017, 2:20pm UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/3 "2017-08-04T14:20:54Z")

</div>

mutually authenticated TLS

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [August 4, 2017, 2:24pm UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/4 "2017-08-04T14:24:18Z")

</div>

You can add client-side certificates to mitmproxy: [http://docs.mitmproxy.org/en/stable/certinstall.html#using-a-client-side-certificate](http://docs.mitmproxy.org/en/stable/certinstall.html#using-a-client-side-certificate)

---

<div class="post-metadata">

**Author:** ![nwwells](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/nwwells/32/182_2.png) [@nwwells](https://discourse.mitmproxy.org/u/nwwells)\
**Post date:** [August 4, 2017, 9:00pm UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/5 "2017-08-04T21:00:48Z")

</div>

Thanks! not sure how I missed that!

---

<div class="post-metadata">

**Author:** ![scobie\_jon](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@scobie\_jon](https://discourse.mitmproxy.org/u/scobie_jon)\
**Post date:** [October 12, 2017, 7:25am UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/6 "2017-10-12T07:25:23Z")

</div>

What about doing mutual authenticated TLS from the client to mitmproxy which then reverse proxies to some other HTTP/HTTPS server?

---

<div class="post-metadata">

**Author:** ![mhils](https://yyz2.discourse-cdn.com/flex030/user_avatar/discourse.mitmproxy.org/mhils/32/7_2.png) [@mhils](https://discourse.mitmproxy.org/u/mhils)\
**Post date:** [October 16, 2017, 2:02am UTC](https://discourse.mitmproxy.org/t/possible-to-reverse-proxy-to-mtls-authenticated-backend/579/7 "2017-10-16T02:02:16Z")

</div>

@scobie_jon: Not sure if that’s a question, but mitmproxy supports that. 😉
