I am looking forward to finally using DNS-PERSIST-01 for validation. No more dynamic DNS updates, DNS credentials or forwarding necessary.
And then the issue is protecting the private key of the issuer and monitoring certificates (it's a good idea to do that anyway).