# Adding a client cert to an upstream service

**URL:** <https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751>\
**Category:** Questions\
**Tags:** service-mesh\
**Created:** [August 24, 2018, 8:31pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751 "2018-08-24T20:31:27Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![rsvenkatesh](https://avatars.discourse-cdn.com/v4/letter/r/e274bd/32.png) [@rsvenkatesh](https://discuss.konghq.com/u/rsvenkatesh)\
**Post date:** [August 24, 2018, 8:31pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/1 "2018-08-24T20:31:27Z")

</div>

An upstream service is protected by certificate authentication and It expects a client certificare, What is the best way to add cert in kong when Kong forwards the request to the upstream service?

---

<div class="post-metadata">

**Author:** ![thibaultcha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/thibaultcha/32/340_2.png) [@thibaultcha](https://discuss.konghq.com/u/thibaultcha)\
**Post date:** [August 24, 2018, 9:21pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/2 "2018-08-24T21:21:28Z")

</div>

Hi @rsvenkatesh ,

As of today, the only way to make Kong use a client certificate when connecting to an upstream is to rely on the [ngx\_http\_proxy\_module](https://nginx.org/en/docs/http/ngx_http_proxy_module.html)’s [proxy\_ssl\_certificate](https://nginx.org/en/docs/http/ngx_http_proxy_module.html#proxy_ssl_certificate) and friends directives.

If you are using Kong 0.14, you can make use of [dynamically injected nginx directives](https://docs.konghq.com/latest/configuration/#injecting-individual-nginx-directives) to achieve this. Otherwise, you’ll have to roll-out your own [custom nginx configuration template](https://docs.konghq.com/latest/configuration/#custom-nginx-templates-embedding-kong) if you are using an older version of Kong.  
The downside of this approach is that _every_ upstream connection will use this certificate, and this isn’t configurable. You _could_ duplicate the Kong `location /` block in a custom nginx configuration template to work around this, such that 2 location blocks are defined, both running Kong, but one of them sets a client certificate, and the other doesn’t.

In the future, we have plans to natively support **dynamic client certificates** , and related work is undergoing at this moment. Please stay tuned for a future release with this feature!

Best,

---

<div class="post-metadata">

**Author:** ![rsvenkatesh](https://avatars.discourse-cdn.com/v4/letter/r/e274bd/32.png) [@rsvenkatesh](https://discuss.konghq.com/u/rsvenkatesh)\
**Post date:** [August 24, 2018, 9:33pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/3 "2018-08-24T21:33:25Z")

</div>

> [@thibaultcha](#):
>
> ou _could_ duplicate the Kong `location /` block in a custom nginx configuration template to work around this, such that 2 location blocks are

Hi @thibaultcha,  
Thank you for your quick response, we are currently actively evaluating Kong and istio and I hope Kong will get this feature out soon, do you have any rough eta on the this feature rollout?

Thank you.  
Venki

---

<div class="post-metadata">

**Author:** ![thibaultcha](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/thibaultcha/32/340_2.png) [@thibaultcha](https://discuss.konghq.com/u/thibaultcha)\
**Post date:** [August 24, 2018, 9:35pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/4 "2018-08-24T21:35:19Z")

</div>

@rsvenkatesh A _very rough_ ETA for this feature would be sometime in the next couple of months. Could be sooner. Pinging @James_Callahan into the conversation as well, as he is heavily involved in the groundwork for this feature.

---

<div class="post-metadata">

**Author:** ![rsvenkatesh](https://avatars.discourse-cdn.com/v4/letter/r/e274bd/32.png) [@rsvenkatesh](https://discuss.konghq.com/u/rsvenkatesh)\
**Post date:** [August 26, 2018, 12:52am UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/5 "2018-08-26T00:52:41Z")

</div>

@thibaultcha Thank you

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 11, 2019, 5:47pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/6 "2019-12-11T17:47:52Z")

</div>

@thibaultcha Hi … is dynamic client certificates supported in kong 1.3 ?

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [December 11, 2019, 5:56pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/7 "2019-12-11T17:56:04Z")

</div>

> [@kumarbijendra](#):
>
> Hi … is dynamic client certificates supported in kong 1.3 ?

See: [Kong upstream SSL mTLS - #15 by datong.sun](https://discuss.konghq.com/t/kong-upstream-ssl-mtls/4544/15) , give upstream mSSL a try in Kong 1.4 . There were some fixes that went in (if your looking to present certs to help w mSSL handshakes that is). Otherwise 1.3 does have the client cert presentation indeed but with a caveat of not being able to validate the upstream certificate.

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 15, 2019, 11:10am UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/8 "2019-12-15T11:10:05Z")

</div>

Hi @jeremyjpj0916

Please guide how to use certificate through “lua\_ssl\_trusted\_certificate”. I have deployed to k8s through helm chart and I have .pem on my local machine.

I have added certificates using end point /certificate and then PATCH services with certificate ID. I have configured routes for this services. But still it give 503, service temporarily unavailable

**My Use Case** : my upstream server has certificate authentication. So I need to make call using client certificate. Hi @jeremyjpj0916 Please guide steps to achieve this.

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 16, 2019, 4:01pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/9 "2019-12-16T16:01:24Z")

</div>

Hi All,

Can someone please guide me on this?

I am using Kong 1.4.2 and _one of my upstream server has certificate authentication._ and I want to proxy using client certificate. How can I do this?  
Steps I am following is :

1. I have added .crt and .key using /certificate API
2. I have configured upstream server with the certificate id created in first step
3. I have configured route  
Now making call using routes, but getting 503 in return. Am I missing something? Does anyone know how to achieve this?

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [December 16, 2019, 5:43pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/10 "2019-12-16T17:43:38Z")

</div>

@kumarbijendra Are you using Kong or Kong Ingress Controller for this?

If Kong Ingress Controller, then you can’t do that yet. The support for it is coming in 0.7  
You can use a build from the master branch to do this as well.

IF you are using Kong, then you need to specify the certificate’s ID in the Service entity in Kong. The service entity has client\_certificate property for this.

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 16, 2019, 5:51pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/11 "2019-12-16T17:51:45Z")

</div>

hi @hbagdi I am using Kong. And, that’s what I explained - while configuring service I have actually specified client\_certificate. Still I am getting 503. Do I need to set any environment variable ? or any other suggestions?

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [December 16, 2019, 5:55pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/12 "2019-12-16T17:55:15Z")

</div>

> [@kumarbijendra](#):
>
> Still I am getting 503.

HTTP 503 is service unavailable and not an authentication problem.  
You should make sure that the response is coming from upstream service or Kong and based on that do further debugging.

That’s all I can say based on the info you’ve provided.

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 16, 2019, 6:06pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/13 "2019-12-16T18:06:58Z")

</div>

Hi @hbagdi,

I am giving some information here:

**GET call on /certificates :**  
{  
“next”: null,  
“data”: [  
{  
“created\_at”: 1576440335,  
“cert”: “-----BEGIN CERTIFICATE-----  
\n-----END CERTIFICATE-----\n”,  
“id”: “866814d8-e0ab-4353-a8db-00cff0b7da57”,  
“tags”: null,  
“key”: “-----BEGIN PRIVATE KEY-----  
\n-----END PRIVATE KEY-----\n”,  
“snis”: [  
“some snis”  
]  
}  
]  
}

**GET call on /services :**  
{  
“next”: null,  
“data”: [  
{  
“host”: “some-host”,  
“created\_at”: 1576440685,  
“connect\_timeout”: 60000,  
“id”: “559723b4-1d97-4acb-8dbf-418abc6c4e8c”,  
“protocol”: “https”,  
“name”: “config-svc-health”,  
“read\_timeout”: 60000,  
“port”: 443,  
“path”: “/bifrost-configurator/api/health”,  
“updated\_at”: 1576441105,  
“retries”: 5,  
“write\_timeout”: 60000,  
“tags”: null,  
“client\_certificate”: {  
“id”: “866814d8-e0ab-4353-a8db-00cff0b7da57”  
}  
}  
]  
}  
**GET On /routes**  
{  
“id”: “0a081087-b68e-47e6-84b6-46945a535e66”,  
“tags”: null,  
“updated\_at”: 1576444412,  
“destinations”: null,  
“headers”: null,  
“protocols”: [  
“http”,  
“https”  
],  
“created\_at”: 1576444412,  
“snis”: null,  
“service”: {  
“id”: “559723b4-1d97-4acb-8dbf-418abc6c4e8c”  
},  
“name”: null,  
“preserve\_host”: false,  
“regex\_priority”: 0,  
“strip\_path”: true,  
“sources”: null,  
“paths”: [  
“/config-svc-health”  
],  
“https\_redirect\_status\_code”: 426,  
“hosts”: [  
“some host”  
],  
“methods”: null  
}

**curl -i -X GET [https://host/kong/config-svc-health](https://host/kong/config-svc-health)**

HTTP/2 503  
server: openresty/1.15.8.2  
date: Mon, 16 Dec 2019 18:06:02 GMT  
content-type: text/html; charset=UTF-8  
content-length: 203  
strict-transport-security: max-age=15724800; includeSubDomains  
x-kong-upstream-latency: 11  
x-kong-proxy-latency: 41  
via: kong/1.4.2

503 Service Temporarily Unavailable
# 503 Service Temporarily Unavailable

* * *
openresty/1.15.8.2

**Kong logs:**  
10.244.2.59 - - [16/Dec/2019:19:44:24 +0000] “GET /config-svc-health HTTP/1.1” 503 203 “-” “curl/7.61.1”

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [December 17, 2019, 6:09pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/14 "2019-12-17T18:09:06Z")

</div>

Please make sure that Kong can talk to the upstream server.

HTTP 503 means that your upstream service is not available. It doesn’t mean that Kong can’t authenticate itself.

Please make sure that Kong can at least connect to your upstream service.

---

<div class="post-metadata">

**Author:** ![kumarbijendra](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/kumarbijendra/32/1550_2.png) [@kumarbijendra](https://discuss.konghq.com/u/kumarbijendra)\
**Post date:** [December 17, 2019, 8:21pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/15 "2019-12-17T20:21:45Z")

</div>

Thanks, Harry! I tested with mock service with SSL authentication. It worked! Many thanks for your quick response and help.

---

<div class="post-metadata">

**Author:** ![ankshukla](https://avatars.discourse-cdn.com/v4/letter/a/e495f1/32.png) [@ankshukla](https://discuss.konghq.com/u/ankshukla)\
**Post date:** [July 13, 2022, 2:25pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/16 "2022-07-13T14:25:29Z")

</div>

I am using Kong Konnect to configure my Gateways running on Azure AKS. Everything works fine in terms of service and routes. I created a service to the backend [IDRIX TLS Client Authentication Test](https://prod.idrix.eu/secure/). This API responds with the certificate details presented by the client. I created a certificate and uploaded it on Konnect under Certificates and updated the certificate ID under the client certificate in the Service. However, the certificate is not being sent to the API. Every time the API responds that no TLS Client certificate is sent. I used curl to reach the backend by providing the same certificate and the response works correctly.

I checked the pod logs and I see the error  
**invalid reference ‘client\_certificate: {“id”:“59af4051-cada-4224-8418-60b252841959”}’ (no such entry in ‘certificates’), context: ngx.timer**

the certificate with this id exists in the Certificates section on Konnect

---

<div class="post-metadata">

**Author:** ![mlalam](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/mlalam/32/4812_2.png) [@mlalam](https://discuss.konghq.com/u/mlalam)\
**Post date:** [January 16, 2025, 6:50pm UTC](https://discuss.konghq.com/t/adding-a-client-cert-to-an-upstream-service/1751/17 "2025-01-16T18:50:52Z")

</div>

Hi, I am trying to do the same SSL authentication by passing the client cert to upstream. Can you share your setup information in regards to this?

FYI. I can see the certificate coming to kong gateway, but I dont know how I can forward that to the upstream. I cannot use service annotations because the certificate will change based on the client calling the service.
