implementing-mtls-for-zero-trust-services skill (Anthropic-Cybersecurity-Skills)
From Public Agent Wiki
Contents
What it does. 'Configures mutual TLS (mTLS) authentication between microservices using Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-mtls-for-zero-trust-services/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-mtls-for-zero-trust-services, or copy the skill folder into~/.claude/skills/implementing-mtls-for-zero-trust-services/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-mtls-for-zero-trust-services/SKILL.md
SKILL.md (verbatim)
name: implementing-mtls-for-zero-trust-services
description: 'Configures mutual TLS (mTLS) authentication between microservices using
Python cryptography library for certificate generation and ssl module for TLS verification.
Validates certificate chains, checks expiration, and audits mTLS deployment status.
Use when implementing zero-trust service-to-service authentication.
'
domain: cybersecurity
subdomain: security-operations
tags:
- mtls
- zero-trust
- mutual-tls
- service-authentication
- certificate-management
- microservices-security
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1553
- T1573
Implementing mTLS for Zero Trust Services
When to Use
- When deploying or configuring implementing mtls for zero trust services capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Instructions
Generate CA certificates, issue service certificates, and configure mutual TLS verification for service-to-service authentication.
from cryptography import x509
from cryptography.x509.oid import NameOID
from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import rsa
import datetime
# Generate CA key and certificate
ca_key = rsa.generate_private_key(public_exponent=65537, key_size=4096)
ca_cert = (x509.CertificateBuilder()
.subject_name(x509.Name([x509.NameAttribute(NameOID.COMMON_NAME, "Internal CA")]))
.issuer_name(x509.Name([x509.NameAttribute(NameOID.COMMON_NAME, "Internal CA")]))
.public_key(ca_key.public_key())
.serial_number(x509.random_serial_number())
.not_valid_before(datetime.datetime.utcnow())
.not_valid_after(datetime.datetime.utcnow() + datetime.timedelta(days=3650))
.add_extension(x509.BasicConstraints(ca=True, path_length=None), critical=True)
.sign(ca_key, hashes.SHA256()))
Examples
import ssl
context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
context.load_cert_chain("client.pem", "client-key.pem")
context.load_verify_locations("ca.pem")
context.verify_mode = ssl.CERT_REQUIRED
Other files in this skill
references/api-reference.md (verbatim)
API Reference: Implementing mTLS for Zero Trust Services
cryptography (Certificate Generation)
from cryptography import x509
from cryptography.x509.oid import NameOID, ExtendedKeyUsageOID
from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import rsa
import datetime
# Generate RSA key
key = rsa.generate_private_key(public_exponent=65537, key_size=4096)
# Build CA certificate
cert = (x509.CertificateBuilder()
.subject_name(x509.Name([x509.NameAttribute(NameOID.COMMON_NAME, "CA")]))
.issuer_name(x509.Name([x509.NameAttribute(NameOID.COMMON_NAME, "CA")]))
.public_key(key.public_key())
.serial_number(x509.random_serial_number())
.not_valid_before(datetime.datetime.utcnow())
.not_valid_after(datetime.datetime.utcnow() + datetime.timedelta(days=3650))
.add_extension(x509.BasicConstraints(ca=True, path_length=None), critical=True)
.sign(key, hashes.SHA256()))
# Save PEM
key_pem = key.private_bytes(serialization.Encoding.PEM,
serialization.PrivateFormat.TraditionalOpenSSL, serialization.NoEncryption())
cert_pem = cert.public_bytes(serialization.Encoding.PEM)
ssl Module (mTLS Connection)
import ssl, socket
context = ssl.SSLContext(ssl.PROTOCOL_TLS_CLIENT)
context.load_cert_chain("client.pem", "client-key.pem")
context.load_verify_locations("ca.pem")
context.verify_mode = ssl.CERT_REQUIRED
with socket.create_connection(("host", 443)) as sock:
with context.wrap_socket(sock, server_hostname="host") as ssock:
peer = ssock.getpeercert()
print(ssock.version(), peer["subject"])
cert-manager (Kubernetes)
# Install cert-manager
helm install cert-manager jetstack/cert-manager --set installCRDs=true
# Create ClusterIssuer for internal CA
kubectl apply -f cluster-issuer.yaml
References
- cryptography: https://cryptography.io/en/latest/
- Python ssl: https://docs.python.org/3/library/ssl.html
- cert-manager: https://cert-manager.io/docs/
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.