Update tls-cert-auth.mdx

This commit is contained in:
Daniel Hougaard
2025-07-17 00:08:34 +04:00
parent a94a26263a
commit 60438694e4

View File

@@ -42,10 +42,14 @@ To be more specific:
Most of the time, the Infisical server will be behind a load balancer or Most of the time, the Infisical server will be behind a load balancer or
proxy. To propagate the TLS certificate from the load balancer to the proxy. To propagate the TLS certificate from the load balancer to the
instance, you can configure the TLS to send the client certificate as a header instance, you can configure the TLS to send the client certificate as a header
that is set as an [environment that is set as an [environment variable](/self-hosting/configuration/envars#param-identity-tls-cert-auth-client-certificate-header-key).
variable](/self-hosting/configuration/envars#param-identity-tls-cert-auth-client-certificate-header-key).
</Accordion> </Accordion>
<Note>
Infisical US/EU and dedicated instances are deployed with AWS ALB. TLS Certificate Auth must flow through our ALB mTLS pass-through in order to authenticate.
When you are authenticating with TLS Certificate Auth, you must use the port `8433` instead of the default `443`. Example: `https://app.infisical.com:8433/api/v1/auth/tls-cert-auth/login`
</Note>
## Guide ## Guide
In the following steps, we explore how to create and use identities for your workloads and applications on TLS Certificate to In the following steps, we explore how to create and use identities for your workloads and applications on TLS Certificate to
@@ -123,7 +127,7 @@ try {
const clientCertificate = fs.readFileSync("client-cert.pem", "utf8"); const clientCertificate = fs.readFileSync("client-cert.pem", "utf8");
const clientKeyCertificate = fs.readFileSync("client-key.pem", "utf8"); const clientKeyCertificate = fs.readFileSync("client-key.pem", "utf8");
const infisicalUrl = "https://app.infisical.com"; // or your self-hosted Infisical URL const infisicalUrl = "https://app.infisical.com:8433"; // or your self-hosted Infisical URL
const identityId = "<your-identity-id>"; const identityId = "<your-identity-id>";
// Create HTTPS agent with client certificate and key // Create HTTPS agent with client certificate and key