Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
🍱 Sean ☕
🍱 Sean ☕
@GigaByte4711@whitespashe.uk  ·  activity timestamp 3 days ago

Just managed to get my first Client SSL authentication working with PFSense and HAProxy!

Getting to understand the ACL ordering was my biggest hurdle, but I can now reject access to my internal apps from the wider internet unless theyre using a client certificate. There's even a bypass for internal IP addresses so I don't need to resort to split-brained DNS!

#sysadmin #haproxy #pfsense #homelab

  • Copy link
  • Flag this post
  • Block
🍱 Sean ☕
🍱 Sean ☕
@GigaByte4711@whitespashe.uk replied  ·  activity timestamp 3 days ago

I'm pleased to say I've been able to write a Tutorial series on how to get a quick-and-dirty implementation of Client Certificate Authentication using PFSense and HAProxy!

Feel free to have a read here:
https://seantodd.co.uk/series/client-certificate-authentication-in-pfsense-with-haproxy/

#sysadmin #haproxy #pfsense #homelab

Sean's Blog

Client Certificate Authentication in PFSense With HAProxy

Friendly Neighbourhood SysAdmin. I write about my homelab and home network.
  • Copy link
  • Flag this comment
  • Block
dch :flantifa: :flan_hacker:
dch :flantifa: :flan_hacker:
@dch@bsd.network replied  ·  activity timestamp 3 days ago

@GigaByte4711 nice! I hope you can share some of these magic tips

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct