PingFederate 13.0.4 (July 2026)
Resolved issues
Client certificate authentication behind proxy
Fixed PF-39335
We fixed a defect where PingFederate, when deployed behind an mTLS proxy, used the TLS layer certificate (the proxy’s server certificate) instead of the client certificate forwarded in the configured client certificate header. This caused client certificate authentication to fail when the proxy terminated mTLS from the client.
Learn more in Configuring incoming proxy settings.