Skip to content

mTLS and certificate pinning

Tested with: cert-manager 1.16 · TrustKit 3.0 · Android Network Security Config (API 24+)

On Team, Enterprise and any instance with secure placement you can require a client certificate in addition to the password. You upload your own CA; the gateway verifies the client certificate against it and writes the certificate subject into the audit log for every connection.

Upload the CA under Network → mTLS in the portal, or set it through the API (client_ca_pem replaces the current bundle; null turns mTLS off):

shell
jq -n --rawfile ca clients-ca.pem '{client_ca_pem: $ca}' | zb api PUT /v1/orgs/{org}/instances/pg-prod/network -d -

Postgres example with a client certificate:

Connection URI
postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full&sslrootcert=databasezy-ca.pem&sslcert=client.pem&sslkey=client-key.pem

Pin the intermediate CA, not the leaf: leaves rotate every 60 days. Rotation dates for the intermediate are published twelve months ahead under Settings → Certificates and on the status page.

AppDelegate.swift
import TrustKit
let config: [String: Any] = [
kTSKSwizzleNetworkDelegates: true,
kTSKPinnedDomains: [
"us-east.databasezy.com": [
kTSKIncludeSubdomains: true,
kTSKEnforcePinning: true,
kTSKPublicKeyHashes: [
"<current intermediate SPKI sha256, base64>",
"<next intermediate SPKI sha256, base64>" // always ship the next pin too
],
],
],
]
TrustKit.initSharedInstance(withConfiguration: config)

Every endpoint satisfies ATS: TLS 1.2+, forward-secrecy suites, SHA-256 certificates, 2048-bit or stronger keys. No ATS exceptions are needed for *.databasezy.com.