There are some services that I expose to the internet (using Apache reverse proxy) that really should be accessed by only a small set of devices. Requiring client certificates seems like a great way to reduce the attack surface and prevent brute force attacks (since the attacker doesn’t even get a chance to attempt a login).
I wonder about the difficulty on the client side as well as other practical implications. The clients are smartphones of various makes.
I use it for Home Assistant and ntfy in combination with Caddy. Certificates are managed by Vaultls (https://github.com/7ritn/VaulTLS) which makes it quite easy to setup and use on new devices.
I use mTLS with Caddy to expose some of my services. It is quite manageable, and I only use if for myself and my wife.
We both use Android phones, and I configure access via apps for the services, that use the devices’ certificate store. It seems like the iOS way is to provide the client certificate and password to each app that’s gonna use it. I’m happy we can avoid that.
Big plus side for us is the simplicity of it all, there is no “always on VPN” requirement, and things “just work” with acceptable security.
I also sometimes access the services via Firefox, which is also able to use the device’s certificate store, although I have to keep selecting the same certificate each time.
It can be a pain to manage but it works well once it is setup
Just make sure it isn’t your only line of defense
I am using mTLS implemented by nginx to access my services like Home Assistant, Paperless, Tandoor, Immich and so on. Clients are Windows, Linux and Android based so no iOS experience. Adding new clients can be tricky if you need to figure out how to provide the certificate first. Once it works, it’s rock solid
It’s a good option if you can’t do anything better, like a VPN. Because there is always the risk of an authentication bypass vulnerability. The less attack surface, the better.
Ditto VPN vulnerabilities. Belt and suspenders can help though if a remote is compromised likely all the things it uses will be, if not immediately then eventually.