I've added a new extension to the PROXY protocol to funnel the full client certificate! This unlocks backend-specific client certificate checks, e.g. verifying from a list of trusted certificates. Thanks to this client certificate authentication can be used with soju behind a TLS termination reverse proxy such as tlstunnel.

git.haproxy.org/?p=haproxy.git

0

If you have a fediverse account, you can quote this note from your own instance. Search https://hachyderm.io/users/emersion/statuses/115926703726974617 on your instance and quote it. (Note that quoting is not supported in Mastodon.)