hazel.blue VPN

IKEv2 road-warrior VPN with certificate authentication — client keys live in device hardware (Secure Enclave, TPM, YubiKey) and never leave it. Certificates come from the private CA.

iPhone

  1. The device serial (Settings → General → About) must be allowlisted in the CA policy (nix-config, allowedDeviceSerials) and etta rebuilt.
  2. On home WiFi, open vpn.hazel.blue.mobileconfig in Safari, then install it via Settings → General → VPN & Device Management. iOS enrolls against the CA during install — the Secure Enclave generates the key, Apple attests the serial.
  3. Keep any old VPN profile until the new one connects, then remove it.

Renewal (1-year certificates, no MDM): reinstall the profile the same way.

Windows

TPM-bound machine certificate via certreq + step ca sign — enrollment script to appear here.


Connection details: server vpn.hazel.blue, IKEv2, EC-256 server certificate (Let's Encrypt), split tunnel for 10.192.0.0/23 and 10.192.7.0/24.