luci.raf.cc { reverse_proxy 192.168.0.1:8002 tls { client_auth { mode require_and_verify trusted_ca_cert_file /srv/admin/ca.crt } } }