When an access list contains client CAs, the combined CA auth file is added to all location blocks via an `if` statement. This allows LetsEncrypt and other support paths to work, while correctly denying access to the protected resources.
- Changes for objection migration - Moved common access template code to an include - Fixed access rules configuration generation