Not sure if you'll see this or if it's directly related. I also domain map but on an Apache server, this is probably an excuse but while I realize Let's Encrypt is free, and although there is the 90-day thing that you could automate, I just go with the year-long $9.00 certificate for each domain. I was wondering though, since it's domain mapped, the root domain can bridge to other sites by subfolders eg.
/var/www/html/main-domain | https://mainsite.com
/var/www/html/main-domain/domain2 | https://somesite.com
/var/www/html/main-domain/domain3 | https://somesite2.com
My question I could just easily try it, I'm not sure if it's related to what you mentioned where if you switch domains while logged into one if you'll lose session. I don't expect it to work. I just don't know what happens if people figured out "hey this ip is hosting multiple sites" and could figure out how to traverse each subfolder-site.
My question sucks sorry. I'll have to try it out I guess, at least my stuff is for myself not dealing with other people's info/sites.
This quesiton is related to information leak. I handle the domain mapping with virtualhosts. I also realized when you switch from say non-www to www (I saw you should stick with one) but when you do that you'll lose the session value so I imagine I'm safe.
I actually just took down one site as it was a useless domain so I can't test the multiple ssl certificates at the moment. Yeap this question is a waste of time my bad.