aws / aws/serverless-java-container

API Gateway MTLS "clientCert" Availability?

Open
#469 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
1.6k
Forks
574
PR merge metrics
No merged PRs in 30d

Description

*Serverless Java Container version*: `eg. 1.5`
1.6

*Implementations:* `Jersey / Spring / Spring Boot / Spring Boot 2 / Spark`
Spring Boot

*Framework version:* `eg SpringBoot 2.2.6.RELEASE`
2.6.6

*Frontend service:* `REST API / HTTP API / ALB`
REST API

## Scenario
I am utilizing MTLS authentication for my API Gateway: https://aws.amazon.com/blogs/compute/introducing-mutual-tls-authentication-for-amazon-api-gateway/

In the documentation, it mentions that the `clientCert` is populated in the API GW's event payload when it is passed along to Lambda authorizers via the `requestContext`.

I want to base my authorization on the clientCert's subjectDN's CN within my java code, but I am not sure if it's possible or how I can access the `clientCert` from within my Java lambda utilizing aws-serverless-java-container. (I realize the lambda isn't a `lambda authorizer`, but I was hoping it may still be accessible) Any suggestions?

## Expected behavior
I would expect that `clientCert` is available within `AwsProxyRequest`'s `AwsProxyRequestContext`
EX:
```"requestContext": {
"authentication": {
"clientCert": {
"clientCertPem": "-----BEGIN CERTIFICATE-----\nMIIEZTCCAk0CAQEwDQ...",
"issuerDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Private CA",
"serialNumber": "1",
"subjectDN": "C=US,ST=Washington,L=Seattle,O=Amazon Web Services,OU=Security,CN=My Client",
"validity": {
"notAfter": "Aug 5 00:28:21 2120 GMT",
"notBefore": "Aug 29 00:28:21 2020 GMT"
}
}
},
...
```

## Actual behavior
I don't see anything in `AwsProxyRequest` or `AwsProxyRequestContext` related to certs or authentication.

## Steps to reproduce
Set up a REST API Gateway pointing to your `aws-serverless-java-container` lambda. Add custom domain. Create certs. Enable MTLS. Make call to the REST API Gateway and attempt to find `clientCert` object from API GW event payload.

## Full log output
N/A

Contributor guide

Open the contributing guide

Research direction

Start by inspecting AwsProxyRequest and AwsProxyRequestContext, then compare their available fields with the API Gateway event payload shown in the issue. Verify the REST API Gateway MTLS request path and determine whether the clientCert data reaches the Java container. Done means the supported request context exposes the certificate information or clearly documents that it is unavailable.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, java
Domain
api
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.