always thought that using *.domain.net for home-use was cool, because that way random people don't know what kinds of subdomains i use.
turns out they can find it out by just checking all the certs for my domain. well. the more you know.
I had the same horrified realization a few years ago when someone explained Certificate Transparency[1] to me.
sounds like i got myself a project for this weekend, implement a wildcard cert for my rev-proxy at home :)
EDIT: i guess the logs would still show the old certs, so my subdomains would still be exposed. huh. at least future subdomains would be hidden.
EDIT2: are there more ways for subdomains to get exposed, other than through DNS or SSL-Certs?
i got a wildcard-cert, implemented it on my proxy, everything works!
unfortunately, to be stealthy, i almost have to switch to a different domain. then request a new public IP, and switch.
anyways, what i liked about caddy was how easily it handles SSL-certs, for sure makes it easier to use! :) gonna have to look into how i can give a wildcard-cert to my rev-proxy.