Cloudflare Workers adds RFC 9440 mTLS certificate fields
Key Points
- Four new RFC 9440 mTLS certificate fields added to Workers
- Direct certificate forwarding without custom parsing
- Size limits: 10KB for certs, 16KB for chains
Summary
Cloudflare Workers now provides four new fields in request.cf.tlsClientAuth for handling mutual TLS (mTLS) client certificates. These fields encode client certificates and intermediate chains in RFC 9440 format, enabling direct forwarding to origins without custom parsing.
Key Points
- New RFC 9440 fields:
certRFC9440,certRFC9440TooLarge,certChainRFC9440,certChainRFC9440TooLarge - Size limits: Client certificates limited to 10KB, intermediate chains to 16KB
- Direct forwarding: Compatible with
Client-CertandClient-Cert-ChainHTTP headers - Error handling: Boolean flags indicate when certificates exceed size limits
- Simplified workflow: No custom parsing or encoding logic required for certificate forwarding