Authentication and client certificates
TrustWeaver uses mutual TLS (mTLS) for authentication, requiring a valid client certificate for every API call.
All communication with TrustWeaver is secured through SSL/TLS with client authentication. This means both the client and the server authenticate each other during the SSL handshake using X.509 certificates. All TrustWeaver signing operations reject requests without a valid client certificate.
How authentication works
When your application connects to TrustWeaver, the SSL handshake performs the following:
- Server authentication
- Your application verifies the server's certificate. Include the Certificate Authority (CA) certificate of the TrustWeaver server certificate in your trust store. Confirm the certificate's validity, signature, revocation status, and host name.
- Client authentication
- TrustWeaver verifies your client certificate. Your application must have access to a valid client certificate and its corresponding private key.
The SSL/TLS channel provides both confidentiality through encryption and authentication of both parties.
Client certificate requirements
Your client certificate must meet the following conditions:
-
Issued by Sovos for your specific environment (UAT or production).
-
Not expired or revoked and trusted by TrustWeaver.
-
Accessible to your application at runtime, along with its corresponding private key.
Request a certificate
Contact Sovos support to request a client certificate for each environment you need access to. When you request a certificate, specify whether it is for UAT or production.
Install a client certificate
How you install the client certificate depends on your client environment. A common approach is to import a password-protected PFX file into your platform's key store. Your Web Services stack then references the key store when establishing the SSL connection.
After installation, configure your stack to present the client certificate during the SSL handshake. The exact configuration steps vary by platform and stack.
Certificate checks on the server certificate
When your application authenticates the TrustWeaver server, perform the following checks on the server certificate:
- Validity
- The certificate is within its valid date range
- Signature validation
- The certificate was signed by a trusted CA
- Revocation
- The certificate hasn't been revoked (CRL or OCSP check)
- Host name
- The certificate matches the host you are connecting to
