There are some services that I expose to the internet (using Apache reverse proxy) that really should be accessed by only a small set of devices. Requiring client certificates seems like a great way to reduce the attack surface and prevent brute force attacks (since the attacker doesn’t even get a chance to attempt a login).
I wonder about the difficulty on the client side as well as other practical implications. The clients are smartphones of various makes.


I use it for Home Assistant and ntfy in combination with Caddy. Certificates are managed by Vaultls (https://github.com/7ritn/VaulTLS) which makes it quite easy to setup and use on new devices.