Identity connectivity with mTLS
Mutual Transport Layer Security (mTLS) is an end-to-end security protocol that verifies the identity of both sides of a communication stream—the client and the Pismo platform. It provides mutual authentication between client and server, ensuring that both parties verify each other's identities before establishing a secure connection.
mTLS is mandatory for all API calls to the Pismo platform. This protocol keeps the platform in compliance with legal requirements, such as the European Union's Electronic Identification, Authentication, and Trust Services (eIDAS) regulation and the revised Payment Services Directive (PSD2).
To configure mTLS, contact your Pismo representative.
- Generate a private key and a Certificate Signing Request (CSR).
- Ensure the CSR follows the Pismo-approved format and requirements.
- Send only the CSR to Pismo through a secure channel.
- Pismo validates and signs the CSR and returns the signed certificate.
- Install the signed certificate together with the corresponding private key in your environment.
The private key must remain secure and must never be shared with Pismo or any third party under any circumstances. You should only provide the CSR to Pismo.
CSR Requirements
- To ensure the certificate can be successfully issued, the CSR must comply with Pismo's required format and specifications.
- Detailed instructions and the CSR template are not publicly available and are provided directly by the Pismo Customer Success or Implementation team upon request.
- Contact your Pismo representative to obtain the latest CSR requirements before you generate and submit a CSR.
How the mTLS process works
The following is an overview of how the authentication process works on the Pismo platform. During the process, if either side fails to present a valid certificate, the connection drops and no data is transmitted in either direction.
- You connect to the platform.
- The platform sends its TLS certificate.
- You verify the certificate.
- You send your certificate to the platform.
- The platform verifies the certificate.
- The platform grants access to you.
- Data exchange occurs securely over the encrypted TLS connection.
Important security details
The Pismo platform enforces strict security controls for all API communications.
Security notes
- mTLS is mandatory for all API calls to the Pismo platform.
- Client certificates are required for authentication and must be valid and trusted.
- Certificates have a defined validity period of two years and must be renewed before expiration.
- Additional security layers are in place to monitor and protect traffic against unauthorized access and malicious activity.
- The private key must remain secure and must never be shared with Pismo or any third party under any circumstances. Only the CSR should be provided to Pismo.
Requests that do not meet authentication or security requirements will be rejected.
For security reasons, detailed error responses and specific validation rules are not publicly documented. If needed, please contact support for troubleshooting assistance: report the incident to Pismo.
Updated 1 day ago
What’s Next
For general security information related to the Pismo platform, refer to: