As I understand it,end-to-end means application to application (endpoint to endpoint?) with assurance to the client that no middleware can intercept traffic successfully. Always thought TLS only assured the presenter of the ServerCertificate is authenticated for the subject,that is to say the client cannot say "I am sure this is the server I meant to communicate with",it can only say "The server I'm speaking with has authority to communicate on behalf of my intended peer"