# Mutual SSL for Rancher agent / server?

**URL:** <https://forums.suse.com/t/mutual-ssl-for-rancher-agent-server/7545>\
**Category:** Rancher 1.x\
**Created:** [October 11, 2017, 6:20pm UTC](https://forums.suse.com/t/mutual-ssl-for-rancher-agent-server/7545 "2017-10-11T18:20:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wtopace](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wtopace/32/3738_2.png) [@wtopace](https://forums.suse.com/u/wtopace)\
**Post date:** [October 11, 2017, 6:20pm UTC](https://forums.suse.com/t/mutual-ssl-for-rancher-agent-server/7545/1 "2017-10-11T18:20:49Z")

</div>

Is mutual SSL / client certificate authentication supported by the Rancher agent?

We already have an Apache reverse proxy in front of the Rancher server to provide SSL, however, we would also like to do an SSLVerifyClient Require to prevent unauthorized (or any really) access to the Rancher API without a valid client certificate.

Thanks!

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [October 14, 2017, 12:38am UTC](https://forums.suse.com/t/mutual-ssl-for-rancher-agent-server/7545/2 "2017-10-14T00:38:01Z")

</div>

We do not currently support this or have any immediate plans to.

The UI, CLI, etc are consumers of the same API, so e.g. all user browsers would have to have certs.

---

<div class="post-metadata">

**Author:** ![wtopace](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/wtopace/32/3738_2.png) [@wtopace](https://forums.suse.com/u/wtopace)\
**Post date:** [October 16, 2017, 3:59pm UTC](https://forums.suse.com/t/mutual-ssl-for-rancher-agent-server/7545/3 "2017-10-16T15:59:24Z")

</div>

Thanks Vincent!

I think we’ll try to implement some kind of split interface design where users of a public vip are required to present a client certificate, however, API users will have their own endpoint that doesn’t require one.
