The Home Assistant App Locked To A Certificate, With nginx Or Caddy And No Cloudflare
Locking the Home Assistant app to a client certificate with nginx or Caddy at home, with step-ca as the certificate authority instead of Cloudflare. What changes when Cloudflare leaves the path, an nginx config and a Caddy config each tested with no certificate, a good one, a revoked one and a WebSocket upgrade over IPv4 and IPv6, why nginx can check a CRL and Caddy can only keep an allowlist, the Home Assistant trusted-proxy settings, what the phone needs installed, and where it falls down.