Mutual TLS requires authentication in both directions. The Mule HTTP Listener acts as the TLS server, so it needs a keystore containing its private key and associated server certificate. This allows the listener to prove its identity to the connecting client.
For mTLS, the server must additionally authenticate the client certificate. Therefore, the TLS context also requires an appropriate truststore containing the certificate authorities or certificates that the application trusts when validating client certificates.
MuleSoft's TLS documentation provides a two-way authentication example for an HTTP Listener containing both < tls:trust-store > and < tls:key-store > inside the TLS context. MuleSoft's HTTP Listener documentation likewise states that HTTPS requires a keystore for the server and a truststore when two-way authentication is required.
Persistent connections affect HTTP connection reuse and performance, not certificate authentication. A reconnection strategy likewise does not provide the cryptographic identity material required for mTLS.
Therefore, an HTTP Listener configured for mutual TLS requires the correct keystore and truststore configuration.
Reference topics: Mule TLS Context; HTTP Listener HTTPS; keystores; truststores; mutual TLS/two-way authentication.
Official documentation: https://docs.mulesoft.com/mule-runtime/4.6/tls-configuration
Official documentation: https://docs.mulesoft.com/http-connector/latest/http-listener-ref
===============================================================
Submit