top | item 44018852

(no title)

lhamil64 | 9 months ago

I've wondered this too. I have a little home server with some self hosted services, and I use a client cert on the reverse proxy to add an extra layer of security before the user can even reach the app. This works fine when accessing things via the browser, but if you want to use something like a mobile app, it almost certainly won't have support for it. It's up to every single app dev to implement support for passing in a client cert on the http requests.

I suppose a VPN is really the better answer here, but that's a pain if I want to give anyone else access and is less granular.

discuss

order