I had decided to try out Pangolin as authentication for a bunch of AdGuard Home web frontends.

To make it extra super duper secure, I wanted to set up mTLS because the frontends only needed to be accessed by a small number of machines.

Of course, setting anything related to SSL is always a royal PITA for me.

There are two client certificates. One for newt which is passwordless since there seemed to be no way to pass in a password when starting it up from the command line. And a second for iOS related devices which required a certificate with a password. Both of these may not be correct but I couldn’t find a way around them.

CA Keys

# Generate CA private key
openssl genrsa -out ca-key.pem 4096
 
# Generate CA certificate
openssl req -new -x509 -days 365 -key ca-key.pem -out ca-cert.pem -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=Pangolin-CA"

Copy ca-cert.pem to the Pangolin server.

Newt Keys

# Generate private key
openssl genrsa -out newt-client-key.pem 4096
 
# Generate certificate signing request
openssl req -new -key newt-client-key.pem -out newt-client.csr -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=newt-client"
 
# Sign the certificate with CA
openssl x509 -req -days 365 -in newt-client.csr -CA ca-cert.pem -CAkey ca-key.pem -CAcreateserial -out newt-client.pem
 
# Create PKCS12 bundle for Newt (passwordless)
openssl pkcs12 -export -out newt-client.p12 -inkey newt-client-key.pem -in newt-client.pem -certfile ca-cert.pem -passout pass:

Copy newt-client.p12 to the newt client.

iOS keys

# Generate private key with password protection
openssl genrsa -aes256 -out ios-client-key.pem 4096
# You'll be prompted to enter a password - remember this for iOS configuration
 
# Generate certificate signing request
openssl req -new -key ios-client-key.pem -out ios-client.csr -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=ios-client"
# You'll need to enter the password again
 
# Sign the certificate with CA
openssl x509 -req -days 365 -in ios-client.csr -CA ca-cert.pem -CAkey ca-key.pem -CAcreateserial -out ios-client.pem
 
# Create PKCS#12 bundle for iOS (includes both cert and key)
openssl pkcs12 -export -out ios-client.p12 -inkey ios-client-key.pem -in ios-client.pem -certfile ca-cert.pem
# You'll be prompted for the key password and then to set an export password

Copy ios-client.p12 to your iOS device and click on it and it will say that a new profile has been downloaded. Go ahead and install it.