Description
An API Gateway stage's client_certificate_id selects the client certificate that API Gateway presents to an HTTPS backend. The backend can validate this certificate to accept only trusted API Gateway requests.
Not every stage needs this method. Check whether the backend uses another appropriate authentication method, and configure both sides if it relies on a client certificate. This is separate from TLS between API callers and the gateway.
Potential impact
- Legitimate requests may fail if the backend requires a certificate that the gateway does not present.
- A backend that neither validates the certificate nor has sufficient alternative access controls may accept requests that bypass the gateway.
Remediation
- If this method is required, generate a certificate in API Gateway and set its ID in
client_certificate_id. - Configure a valid server certificate on the HTTPS backend, and require it to validate the trusted gateway client certificate and reject other connections.
- Test the integration and rejection of unauthorized connections, and rotate certificates before expiry. Update the backend's trust configuration during rotation as well.
Examples
These excerpts compare stage settings only. The REST API, deployment, HTTPS integration and backend certificate verification require separate configuration.
Before
resource "aws_api_gateway_stage" "example" {
stage_name = "prod"
rest_api_id = aws_api_gateway_rest_api.test.id
deployment_id = aws_api_gateway_deployment.test.id
}
No client certificate is selected for the stage through this setting. Check whether the backend requires this authentication method.
After
resource "aws_api_gateway_stage" "example" {
stage_name = "prod"
rest_api_id = aws_api_gateway_rest_api.test.id
deployment_id = aws_api_gateway_deployment.test.id
client_certificate_id = var.api_gateway_client_certificate_id
}
Pass the ID of an actual generated certificate through api_gateway_client_certificate_id. This setting alone does not configure the backend to trust or validate it.