Review API Gateway backend client certificate settings

Configure a client certificate when an HTTPS backend must verify calls from API Gateway.

Description

If a backend is designed to verify API Gateway calls through a client certificate, a missing required stage certificate prevents that authentication from being used. ClientCertificateId concerns requests from API Gateway to an HTTPS backend, not the public API’s HTTPS certificate.

The backend must actually validate the certificate for the protection to apply. Not every API needs this certificate if another suitable backend authentication mechanism is used.

Potential impact

  • A backend with neither certificate validation nor other authentication may accept unintended direct calls.
  • Expired certificates or mismatched backend trust settings can cause legitimate requests to fail.

Remediation

Confirm the backend authentication requirements. If using an API Gateway client certificate, generate it, attach it through the stage’s ClientCertificateId and configure the HTTPS backend to validate it. Rotate the certificate before expiration and test legitimate requests and unauthorized direct requests.

Examples

This is a partial REST API stage configuration. Prepare the API, deployment, API Gateway-generated client certificate and HTTPS backend trust settings separately.

Before

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref ApiDeployment

No backend client certificate is specified for the stage. This does not mean that HTTPS for the public API is disabled.

After

yaml
Resources:
  ProdStage:
    Type: AWS::ApiGateway::Stage
    Properties:
      StageName: Prod
      RestApiId: !Ref MyRestApi
      DeploymentId: !Ref ApiDeployment
      ClientCertificateId: !Ref ClientCertificate

ClientCertificateId attaches the certificate used for backend requests. The backend must validate it; authentication of public callers remains separate.

References