Configuring mTLS with Private Locations¶
mTLS is a protocol that allows two parties to authenticate each other and ensure the integrity of the communication.
The Private Location tunnels TLS traffic. For targets that require mTLS, configure a proxy to intercept TLS and present the client certificate to your target. The proxy handles client authentication; the Private Location forwards the traffic.
For example, you can use mitmproxy and configure the mTLS client certificates.
TLS Interception
The scanner must accept the certificate presented by mitmproxy for this setup to work. The agent's ESCAPE_SSL_CERT_PATH and ESCAPE_SSL_INSECURE variables don't affect target TLS. Confirm the scanner's certificate handling before using this setup.
Here's an example Docker Compose file that starts a Private Location and a mitmproxy instance.
Create ./certs/client.pem containing both the client certificate and its unencrypted private key, as required by mitmproxy's client certificate configuration.
---
services:
private-location:
image: escapetech/cli:latest
restart: always
command: locations start -v location-name
environment:
- ESCAPE_API_KEY=<ESCAPE_API_KEY>
- ESCAPE_BACKEND_PROXY_URL=http://mtls-proxy:8080
mtls-proxy:
image: mitmproxy/mitmproxy
restart: always
ports:
- "8080:8080"
volumes:
- ./certs:/certs
command: mitmdump --set client_certs=/certs/client.pem
Note
If the target uses a private CA, configure mitmproxy's upstream trust with ssl_verify_upstream_trusted_ca pointing to a mounted PEM CA file. See the mitmproxy options.