
mTLS for Internal Services: Useful Security or Homelab Theatre, Hands-On
mTLS authenticates both sides of an internal connection, which closes a real hole on a LAN full of devices, and it does not fix application bugs, stop a compromised service, or survive root on the host. A hands-on look at the threat model, client certificates with Caddy and Nginx, service mesh identity, and the mobile apps that cannot present a certificate.





