Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have servers that are firewalled off from the wider internet, or indeed not even reachable (rfc1918 ips)

I could get around it by hosting split dns, but that’s quite messy

Even on those that are reachable I’d have to carve out port 80 and forward it somewhere else to do the cert generation.

Another option would be dynamic server names - where the host part contains a lot of information (or no info)

https://gafjsisi.slashdot.org I suspect has never been loaded before today. It seems to work from my phone so I assume it’s a wildcard cert



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: