←back to thread

246 points nh2 | 2 comments | | HN request time: 0.435s | source
Show context
ndsipa_pomu ◴[] No.41912342[source]
I prefer to assign an external name to an internal device and grab a free SSL cert from LetsEncrypt, but using DNS challenge instead as internal IP addresses aren't reachable by their servers.
replies(9): >>41912368 #>>41912827 #>>41913126 #>>41913387 #>>41913720 #>>41913826 #>>41916306 #>>41917079 #>>41917804 #
1. djhworld ◴[] No.41912827[source]
I last looked at LetsEncrypt maybe 8-9 years ago, I thought it was awesome but not suitable for my internal stuff due to the http challenge requirement, so I went down the self signed CA route and stuck with that, and didn’t really keep up with developments in the space

It was only until recently someone told me about the DNS challenge and I immediately ported everything over with a wildcard cert - its been great!

replies(1): >>41914886 #
2. bmicraft ◴[] No.41914886[source]
They've introduced the dns challenge almost 9 years ago, you must have barely missed it!