Why not just fetch a different cert for every subdomain you use? It's also better security practice as this allows you to use different key per subdomain and the possibility to revoke bad or unused certs.
Why not just fetch a different cert for every subdomain you use? It's also better security practice as this allows you to use different key per subdomain and the possibility to revoke bad or unused certs.
I could get around it by hosting split dns, but that’s quite messy
Even on those that are reachable I’d have to carve out port 80 and forward it somewhere else to do the cert generation.
Another option would be dynamic server names - where the host part contains a lot of information (or no info)
https://gafjsisi.slashdot.org I suspect has never been loaded before today. It seems to work from my phone so I assume it’s a wildcard cert
Also, if for some reason the automated process fails, I'd rather have one subdomain go down, than all of them.