I had decided to try out Pangolin as authentication for a bunch of AdGuard Home web frontends.
To make it extra super duper secure, I wanted to set up mTLS because the frontends only needed to be accessed by a small number of machines.
Of course, setting anything related to SSL is always a royal PITA for me.
There are two client certificates. One for newt which is passwordless since there seemed to be no way to pass in a password when starting it up from the command line. And a second for iOS related devices which required a certificate with a password. Both of these may not be correct but I couldn’t find a way around them.
CA Keys
# Generate CA private key
openssl genrsa -out ca-key.pem 4096
# Generate CA certificate
openssl req -new -x509 -days 365 -key ca-key.pem -out ca-cert.pem -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=Pangolin-CA"Copy ca-cert.pem to the Pangolin server.
Newt Keys
# Generate private key
openssl genrsa -out newt-client-key.pem 4096
# Generate certificate signing request
openssl req -new -key newt-client-key.pem -out newt-client.csr -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=newt-client"
# Sign the certificate with CA
openssl x509 -req -days 365 -in newt-client.csr -CA ca-cert.pem -CAkey ca-key.pem -CAcreateserial -out newt-client.pem
# Create PKCS12 bundle for Newt (passwordless)
openssl pkcs12 -export -out newt-client.p12 -inkey newt-client-key.pem -in newt-client.pem -certfile ca-cert.pem -passout pass:Copy newt-client.p12 to the newt client.
iOS keys
# Generate private key with password protection
openssl genrsa -aes256 -out ios-client-key.pem 4096
# You'll be prompted to enter a password - remember this for iOS configuration
# Generate certificate signing request
openssl req -new -key ios-client-key.pem -out ios-client.csr -subj "/C=US/ST=State/L=City/O=Pangolin/OU=VPN/CN=ios-client"
# You'll need to enter the password again
# Sign the certificate with CA
openssl x509 -req -days 365 -in ios-client.csr -CA ca-cert.pem -CAkey ca-key.pem -CAcreateserial -out ios-client.pem
# Create PKCS#12 bundle for iOS (includes both cert and key)
openssl pkcs12 -export -out ios-client.p12 -inkey ios-client-key.pem -in ios-client.pem -certfile ca-cert.pem
# You'll be prompted for the key password and then to set an export passwordCopy ios-client.p12 to your iOS device and click on it and it will say that a new profile has been downloaded. Go ahead and install it.