<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Anybody here does mTLS?]]></title><description><![CDATA[<p dir="auto">There are some services that I expose to the internet (using Apache reverse proxy) that really should be accessed by only a small set of devices. Requiring client certificates seems like a great way to reduce the attack surface and prevent brute force attacks (since the attacker doesn't even get a chance to attempt a login).</p>
<p dir="auto">I wonder about the difficulty on the <em>client</em> side as well as other practical implications. The clients are smartphones of various makes.</p>
]]></description><link>https://forum.ieu.app/topic/ee36b4f6-76d2-4b6d-a291-14f7c40ecd9b/anybody-here-does-mtls</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 19:02:36 GMT</lastBuildDate><atom:link href="https://forum.ieu.app/topic/ee36b4f6-76d2-4b6d-a291-14f7c40ecd9b.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 16 Aug 2026 17:22:42 GMT</pubDate><ttl>60</ttl></channel></rss>