<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Nginx on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/nginx/</link>
    <description>Recent content in Nginx on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Fri, 09 Oct 2026 18:20:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/nginx/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Client Certificates From step-ca, And The Defaults That Lock Everyone Out</title>
      <link>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</link>
      <pubDate>Fri, 09 Oct 2026 18:20:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/step-ca-client-certificates-mtls/</guid>
      <description>Using step-ca to issue client certificates for mTLS, tested with nginx and Caddy. The 24-hour limit and how to raise it, a CRL that rejects everyone until its scope is fixed, the root CRL nginx needs, publishing CRLs over HTTP, the refresh job that stops them lapsing, and the PKCS12 file and CA certificates a phone needs.</description>
    </item>
    <item>
      <title>The Home Assistant App Locked To A Certificate, With nginx Or Caddy And No Cloudflare</title>
      <link>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-mtls-nginx-caddy/</link>
      <pubDate>Fri, 09 Oct 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/homeassistant/home-assistant-app-mtls-nginx-caddy/</guid>
      <description>Locking the Home Assistant app to a client certificate with nginx or Caddy at home instead of Cloudflare. What changes when Cloudflare leaves, both configs tested over IPv4 and IPv6, why nginx can check revocation and Caddy cannot, the Home Assistant proxy settings, and what to install on the phone.</description>
    </item>
  </channel>
</rss>
