IKEv2 road-warrior VPN with certificate authentication — client keys live in device hardware (Secure Enclave, TPM, YubiKey) and never leave it. Certificates come from the private CA.
allowedDeviceSerials) and
etta rebuilt.Renewal (1-year certificates, no MDM): reinstall the profile the same way.
TPM-bound machine certificate via certreq +
step ca sign — enrollment script to appear here.
Connection details: server vpn.hazel.blue,
IKEv2, EC-256 server certificate (Let's Encrypt), split tunnel for
10.192.0.0/23 and 10.192.7.0/24.