# mTLS Client Authentication Is Now Supported by Instaclustr for Apache Kafka®

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;mTLS Client Authentication Is Now Supported by Instaclustr for Apache Kafka® 

mTLS Client Authentication Is Now Supported by Instaclustr for Apache Kafka®
============================================================================

May 16, 2023 | By [ Varun Ghai](https://www.instaclustr.com/blog/author/varun-ghai/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=mTLS%20Client%20Authentication%20Is%20Now%20Supported%20by%20Instaclustr%20for%20Apache%20Kafka%C2%AE&url=https://www.instaclustr.com/blog/mtls-client-authentication-supported-by-instaclustr-for-apache-kafka/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/mtls-client-authentication-supported-by-instaclustr-for-apache-kafka/&title=&summary=mTLS%20Client%20Authentication%20Is%20Now%20Supported%20by%20Instaclustr%20for%20Apache%20Kafka%C2%AE&source=) 

We are excited to announce the release of mTLS client authentication for our Instaclustr for Apache Kafka ® offering.

Thus far we provided the option for customers to enable TLS encryption between clients and the Kafka cluster. This allowed the clients to authenticate the broker using a cluster-specific truststore downloaded from the Instaclustr Console or APIs. Now, with the addition of support for mutual TLS (also referred to as mTLS), both parties can authenticate each other and communicate over an encrypted channel.

This new feature extends the current implementation of mTLS in Instaclustr managed Kafka clusters where it is used for securing internal broker-to-broker communication and communication between the Kafka brokers and any enabled add-ons.

We have implemented mTLS client authentication to work in combination with Kafka ACLs (Access Control Lists). So, after the broker and client have authenticated each other, on the broker’s side, the distinguished name (DN) extracted from the certificate provided by the client is used to map it to a Kafka principal, using Kafka ACLs for authorization.

If we’ve piqued your interest, you can read more on how to provision a cluster with mTLS enabled [here](https://www.instaclustr.com/support/documentation/kafka/getting-started-with-kafka/connecting-to-a-kafka-mtls-cluster/), with [this page](https://www.instaclustr.com/support/documentation/kafka/useful-concepts/mtls/) providing some general information on mTLS itself.

The best piece of news about this new feature is you will not have to pay anything extra to access it! All new clusters provisioned on Kafka versions 2.8.2 or later on our managed platform can access it during cluster creation. For customers already running Instaclustr for Apache Kafka clusters on these versions who want to enable this feature, please reach out to our friendly Technical Operations team by [opening a support ticket](https://support.instaclustr.com/hc/en-us/requests/new).

If you aren’t yet a customer, [sign up](https://console2.instaclustr.com/signup) for a free trial account to test our managed Kafka offering with mTLS client authentication.

 

### About the author

**[Varun Ghai](https://www.instaclustr.com/blog/author/varun-ghai/)** | Product Manager

With a keen focus on product management, Varun brings a wealth of experience and expertise to the team, driving innovation and excellence in the company's Apache Kafka offering.

 



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
