Of course, it does look like they support wildcard certs, so it probably won't be cheap.
EDIT: Removed EV reference, these are DV only.
Of course, it does look like they support wildcard certs, so it probably won't be cheap.
EDIT: Removed EV reference, these are DV only.
The official client doesn't support it yet though; you'll have to use alternative clients.
[1]: https://twitter.com/letsencrypt/status/689919523164721152
does this solve that ? Am I now able to bake letsencrypt in my docker images ?
With DNS-based validation you have to create a TXT record on your domain with a random token. If you can automate creation of TXT records from your setup, that would be an option to solve the challenge. The rate limit issue still applies.
This creates issues come renewal time, but a few tweaks to the renewal config (/etc/letsencrypt/renewal/your.domain.conf) fixes that
https://github.com/DanielDent/docker-nginx-ssl-proxy
My solution is to simply include a self-signed dummy keypair that gets replaced by the letsencrypt keys when they get issued.
An alternative approach would be to remove the SSL listener entirely until the certificate is issued.
Does the DNS based validation make this better in any way?
I assume you mean Let's Encrypt's newly announced DNS validation approach to issuance? I think that would only add unnecessary complexity here.
There are other setups where that will be nice to have, but I don't think this is one of them.