Description
If a backend is designed to verify API Gateway calls through a client certificate, a missing required stage certificate prevents that authentication from being used. ClientCertificateId concerns requests from API Gateway to an HTTPS backend, not the public API’s HTTPS certificate.
The backend must actually validate the certificate for the protection to apply. Not every API needs this certificate if another suitable backend authentication mechanism is used.
Potential impact
- A backend with neither certificate validation nor other authentication may accept unintended direct calls.
- Expired certificates or mismatched backend trust settings can cause legitimate requests to fail.
Remediation
Confirm the backend authentication requirements. If using an API Gateway client certificate, generate it, attach it through the stage’s ClientCertificateId and configure the HTTPS backend to validate it. Rotate the certificate before expiration and test legitimate requests and unauthorized direct requests.
Examples
This is a partial REST API stage configuration. Prepare the API, deployment, API Gateway-generated client certificate and HTTPS backend trust settings separately.
Before
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref ApiDeployment
No backend client certificate is specified for the stage. This does not mean that HTTPS for the public API is disabled.
After
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref ApiDeployment
ClientCertificateId: !Ref ClientCertificate
ClientCertificateId attaches the certificate used for backend requests. The backend must validate it; authentication of public callers remains separate.