<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Homelab on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/homelab/</link>
    <description>Recent content in Homelab on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/homelab/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SSH Logins Signed By step-ca: No More authorized_keys</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-ssh-certificates/</link>
      <pubDate>Fri, 09 Oct 2026 18:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-ssh-certificates/</guid>
      <description>Using step-ca as an SSH certificate authority: signing host keys so clients stop asking to trust them, signing user keys so servers need no authorized_keys, the two sshd_config lines and one known_hosts line it takes, what was refused in testing, and renewing host certificates.</description>
    </item>
    <item>
      <title>Client Certificates From step-ca, And The Defaults That Lock Everyone Out</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</link>
      <pubDate>Fri, 09 Oct 2026 18:20:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</guid>
      <description>Using step-ca to issue client certificates for mTLS, tested with nginx and Caddy. The 24-hour limit and how to raise it, a CRL that rejects everyone until its scope is fixed, the root CRL nginx needs, publishing CRLs over HTTP, the refresh job that stops them lapsing, and the PKCS12 file and CA certificates a phone needs.</description>
    </item>
    <item>
      <title>The Home Assistant App Locked To A Certificate, With nginx Or Caddy And No Cloudflare</title>
      <link>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-mtls-nginx-caddy/</link>
      <pubDate>Fri, 09 Oct 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-mtls-nginx-caddy/</guid>
      <description>Locking the Home Assistant app to a client certificate with nginx or Caddy at home instead of Cloudflare. What changes when Cloudflare leaves, both configs tested over IPv4 and IPv6, why nginx can check revocation and Caddy cannot, the Home Assistant proxy settings, and what to install on the phone.</description>
    </item>
    <item>
      <title>Your Own Certificate Authority: step-ca In A Container</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-in-a-container/</link>
      <pubDate>Fri, 09 Oct 2026 17:50:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-in-a-container/</guid>
      <description>Smallstep&amp;#39;s step-ca in a Podman or Docker container as the certificate authority for everything inside the house: why it beats self-signed and public certificates for internal names, the two passwords the image makes, trusting the root, internal HTTPS over ACME, and renewing services that cannot do ACME.</description>
    </item>
    <item>
      <title>The Home Assistant App Over Cloudflare, Locked To A Certificate, On The Free Plan</title>
      <link>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-over-cloudflare-mtls/</link>
      <pubDate>Fri, 09 Oct 2026 16:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-over-cloudflare-mtls/</guid>
      <description>Reaching Home Assistant from the Android app away from home without putting a login page on the internet. The options compared on cost, risk and battery, why Cloudflare Access does not suit the app, the free-plan client certificates and WAF rule that do, the Home Assistant proxy, ban and URL settings, and building the PKCS12 file the phone needs.</description>
    </item>
  </channel>
</rss>
