mTLS and certificate pinning
Tested with: cert-manager 1.16 · TrustKit 3.0 · Android Network Security Config (API 24+)
Requiring client certificates (mTLS)
Section titled “Requiring client certificates (mTLS)”On Team, Enterprise and any instance with secure placement you can require a client certificate in addition to the password. You upload your own CA; the gateway verifies the client certificate against it and writes the certificate subject into the audit log for every connection.
Upload the CA under Network → mTLS in the portal, or set it through the API (client_ca_pem replaces the
current bundle; null turns mTLS off):
jq -n --rawfile ca clients-ca.pem '{client_ca_pem: $ca}' | zb api PUT /v1/orgs/{org}/instances/pg-prod/network -d -Postgres example with a client certificate:
postgresql://app:<password>@pg-7f3k.us-east.databasezy.com:5432/app?sslmode=verify-full&sslrootcert=databasezy-ca.pem&sslcert=client.pem&sslkey=client-key.pemPinning from mobile apps
Section titled “Pinning from mobile apps”Pin the intermediate CA, not the leaf: leaves rotate every 60 days. Rotation dates for the intermediate are published twelve months ahead under Settings → Certificates and on the status page.
import TrustKit
let config: [String: Any] = [ kTSKSwizzleNetworkDelegates: true, kTSKPinnedDomains: [ "us-east.databasezy.com": [ kTSKIncludeSubdomains: true, kTSKEnforcePinning: true, kTSKPublicKeyHashes: [ "<current intermediate SPKI sha256, base64>", "<next intermediate SPKI sha256, base64>" // always ship the next pin too ], ], ],]TrustKit.initSharedInstance(withConfiguration: config)<network-security-config> <domain-config> <domain includeSubdomains="true">us-east.databasezy.com</domain> <pin-set expiration="2027-09-01"> <pin digest="SHA-256"><!-- current intermediate --></pin> <pin digest="SHA-256"><!-- next intermediate --></pin> </pin-set> </domain-config></network-security-config>Apple App Transport Security
Section titled “Apple App Transport Security”Every endpoint satisfies ATS: TLS 1.2+, forward-secrecy suites, SHA-256 certificates, 2048-bit or stronger keys.
No ATS exceptions are needed for *.databasezy.com.