iOS Apple Contacts (CardDAV) via .mobileconfig not presenting client certificate to AWS ALB mTLS

Background

We need to sync corporate contacts to native iOS Apple Contacts via CardDAV, restricted strictly to company-managed devices using mTLS (deployed via .mobileconfig).

Problem

The backend sits behind an AWS ALB with native mTLS enabled (Verify with trust store).

However, ALB logs show that the iOS client fails to present the client certificate during the TLS handshake, causing the ALB to reject the connection (leaf_client_cert_subject: - (empty client cert offered during handshake).

What I Have Verified & Tried

  1. In .mobileconfig, I declared both com.apple.security.pkcs12 and com.apple.carddav.account. However, there seems to be no fields to link the pkcs12 to the carddav account.

  2. Installed Root CA on iOS -> Settings > General > About > Certificate Trust Settings > Enabled "Full Trust For Root Certificates".

  3. I check the CardDAV UI but there is nowhere to add client certificate.

Questions

How to implement mTLS on native iOS Apple Contacts via CardDAV?

iOS Apple Contacts (CardDAV) via .mobileconfig not presenting client certificate to AWS ALB mTLS
 
 
Q