Review certificate identity
A certificate chain can be valid while the certificate belongs to the wrong partner. Check the identity mapping after TLS finishes. Record trusted issuers, certificate purpose, partner mapping, and expiry monitoring. Test a second partner certificate against the first partner’s resource. During renewal, accept only the two intended certificates for the same partner and remove the old mapping at the end of overlap.
Test cases and proof
| Case | Expected result | Proof to keep |
|---|---|---|
| Partner B certificate calls A resource | Deny | Identity mapping log |
| Expired certificate connects | Deny at configured TLS/policy gate | Handshake result |
| Renewed certificate during overlap | Accept only mapped partner | Handshake and API response |
Synthetic example
A valid TLS handshake from partner B does not authorize partner B to read partner A settlements. Map the certificate to B, then apply object access at the API. Test a renewed certificate before and after the old one expires.
Evidence to keep
For each handshake, record the certificate fingerprint, validated issuer, partner mapping, and API response. Under strict handshake enforcement, an expired certificate fails before an HTTP response exists; a valid but wrong-partner certificate can complete TLS and still receive an API denial. This distinction points the fix to the right layer. Keep private keys out of the test report.
Include a test for a certificate that chains to a trusted issuer but lacks the expected partner mapping. A handshake may succeed; the API must still deny partner resources. Record whether the denial occurs before or after routing, since that tells the team which configuration needs repair.
Map the certificate to one partner
A trusted issuer may sign certificates for many clients. Trusting the issuer alone does not tell the API which partner is calling. Use a stable certificate identity mapping and check the requested resource against it. Decide how renewal updates that mapping: the new and old certificate may both be valid for a short overlap, then only the new one. Test an expired certificate at the TLS layer and a wrong-partner certificate at the API layer. Their different failure points matter when staff debug a failed integration.
Related reading
Why these checks matter
RFC 8705 defines certificate-bound OAuth patterns for mutual TLS. OWASP’s authorization guide still calls for a permission decision on each request. A valid client certificate proves a TLS identity; it does not grant that partner every settlement. The test records the handshake and object access as separate results.
Name the TLS enforcement point
Synthetic partner A has certificate CA; B has CB; a third certificate is expired. In strict mTLS, missing or invalid certificates fail at TLS negotiation and no HTTP result exists. Some gateways request a certificate but pass its validation result to an HTTP policy. There a denial can be an HTTP response. Record which design the test endpoint uses before expecting one failure layer.
Call A’s resource with CB. Its valid handshake does not grant A’s data. Call the origin directly from a staging workload and try to set the gateway’s certificate-identity header. The origin must trust that header only over a protected, authenticated gateway path, and the gateway must overwrite client copies. Record certificate fingerprint, validated identity, mapped partner, and object decision.
Test token and certificate together where used
If the API uses certificate-bound OAuth tokens, obtain token TA under CA and then present TA with CB. The resource server must reject the certificate mismatch even if both certificates are otherwise valid. A plain bearer-token API with mTLS needs its own partner-scope check; it does not gain certificate-bound behavior from TLS alone.
During renewal, add the new certificate mapping, test required partner operations, and retire the old mapping at the chosen cut-off. Certificate expiry and application mapping removal are different events. Keep CA private keys out of evidence. RFC 8705 defines OAuth mTLS and certificate-bound tokens; use its mismatch check only when that token mode is deployed.