Mutual TLS - Easy explained


  1. A puts an envelope in a box, locks the box with his key and sends it to B. The box can't be opened on the way, since it is locked.
  2. B receives the box, and accepts to view it. But can't open the box neither, since it is locked.
  3. B lockes the box again, this time with his own lock and sends it back to A.
  4. The box is now locked with 2 locks, one from A, and one from B.
  5. A receives the box and realizes, that B has accepted the communication by locking the box with his lock. 
  6. A can now remove his lock and send the box back to B. 
  7. The box still can't be opened by anyone other than B.
  8. B receives the box with his lock and can now open the box with his own key and open the envelope sent by A originally.
  9. For A and B to trust each others locks (certificates), a Certificate Authority (CA) must approve both certificates.