There are some services that I expose to the internet (using Apache reverse proxy) that really should be accessed by only a small set of devices. Requiring client certificates seems like a great way to reduce the attack surface and prevent brute force attacks (since the attacker doesn’t even get a chance to attempt a login).

I wonder about the difficulty on the client side as well as other practical implications. The clients are smartphones of various makes.

  • BartyDeCanter@piefed.social
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    5 hours ago

    I use Tailscale for this, with my own Headscale server so that I am in control of everything. It’s a much easier approach that is more likely to pass the spousal acceptance factor.

      • observantTrapezium@lemmy.caOP
        link
        fedilink
        English
        arrow-up
        4
        ·
        4 hours ago

        I’m already running Headscale, and it works great. But to expose individual services to individual devices it feels like an overkill. I don’t actually need all these devices to connect to the tailnet all the time, and some of these devices I don’t even want to be able to access the entire tailnet.