<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Support (optional) global HTTPS mutual TLS certificate-based authentication]]></title><description><![CDATA[<p dir="auto">It would be a good addition to the ingress handling on box to be able to optionally configure mutual TLS authentication for connections to the server. This would allow those of us who do use Cloudflare to enable <a href="https://support.cloudflare.com/hc/en-us/articles/204899617-Authenticated-Origin-Pulls#:~:text=An%20origin%20pull%20happens%20whenever%20Cloudflare%20is%20unable,between%20end-user%20web%20browsers%20and%20website%20origin%20servers." target="_blank" rel="noopener noreferrer nofollow ugc">Authenticated Origin Pulls</a>, and would further allow others who perhaps would like to have a remotely located server only accessible to certain network(s) via a proxy/gateway to do so without the overhead and technically not recommended approach of a VPN connection to the box itself. Similarly, this relieves the need to depend on expensive private ingress solutions (generally also VPN-based) into otherwise inaccessible VPCs of most cloud providers.</p>
<p dir="auto">This would necessarily have to only apply to the HTTP/S side of inbound traffic, I expect, which would be reasonable, since it is a rather specific protocol layering and I don't believe such a mechanism is necessary or supported for some of the other services that can be operated on a Cloudron installation. This may or may not also need to exclude the actual <code>my.example.com</code> management interface, also a fair compromise to my mind.</p>
]]></description><link>https://forum.cloudron.io/topic/3826/support-optional-global-https-mutual-tls-certificate-based-authentication</link><generator>RSS for Node</generator><lastBuildDate>Thu, 16 Apr 2026 04:44:10 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/3826.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 01 Dec 2020 14:35:06 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Support (optional) global HTTPS mutual TLS certificate-based authentication on Sat, 15 Jul 2023 21:23:06 GMT]]></title><description><![CDATA[<p dir="auto">I understand the use case might be a bit narrow, but for those who understand - that's an absolute killer.</p>
]]></description><link>https://forum.cloudron.io/post/70297</link><guid isPermaLink="true">https://forum.cloudron.io/post/70297</guid><dc:creator><![CDATA[potemkin_ai]]></dc:creator><pubDate>Sat, 15 Jul 2023 21:23:06 GMT</pubDate></item><item><title><![CDATA[Reply to Support (optional) global HTTPS mutual TLS certificate-based authentication on Tue, 16 Feb 2021 14:47:45 GMT]]></title><description><![CDATA[<p dir="auto">Makes a lot of sense.</p>
]]></description><link>https://forum.cloudron.io/post/25951</link><guid isPermaLink="true">https://forum.cloudron.io/post/25951</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 16 Feb 2021 14:47:45 GMT</pubDate></item></channel></rss>