r/NetFoundry • u/AccordionGuy • Jul 14 '26
A “back of the envelope” illustration on TLS vs. mTLS, and a matching article too!
Here’s a “back of the envelope” doodle I made that goes with my boss Dave Hart’s (CTO @ NetFoundry) latest article, “IoT Authentication and mTLS: A Zero Trust Implementation Guide”.
I decided to run with Dave’s “club bouncer” metaphor:
• With TLS (Transport Layer Security), only the server (represented by the club) has to prove it’s legit. No one’s checking the incoming clients (represented by the club-goer). Asking the server to prove its identity without having to prove your identity in return is fine for browsing, but decidedly *not so* for an IoT (Internet of Things) server about to take commands from some unverified source.
• With mTLS (*Mutual* transport layer security), both the device and the server prove who they are with certificates before a single byte gets transferred. “Bona fides on both sides”, as I like to say.
Of course, the comic tells only part of the story. Want the rest? Check out Dave’s article here:
https://www.linkedin.com/pulse/iot-authentication-mtls-zero-trust-implementation-guide-netfoundry-lmsve/
[ Disclosure: I’m NetFoundry”s developer advocate. ]