There are some services that I expose to the internet (using Apache reverse proxy) that really should be accessed by only a small set of devices. Requiring client certificates seems like a great way to reduce the attack surface and prevent brute force attacks (since the attacker doesn’t even get a chance to attempt a login).

I wonder about the difficulty on the client side as well as other practical implications. The clients are smartphones of various makes.

  • Mike Wooskey@lemmy.thewooskeys.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    3 hours ago

    MTLS is great protection, but the use case must support it. For example, if you want your app to support registration for new accounts or if you have a lot of people you want to have access, that might make mTLS unwieldy to manage.

    I host apps behind Traefik reverse proxy, using the d.rymcg.tech framework. It make it easy to protect your apps behind HTTP basic auth, Oauth2, or mTLS(or any combination).