2 ms·
Not a bad question. You are correct, the ELBs are doing ssl termination, but the way I'm using Let's Encrypt and a 3rd party python script means that each web s
by twothamendment 11y ago
Not a bad question. You are correct, the ELBs are doing ssl termination, but the way I'm using Let's Encrypt and a 3rd party python script means that each web server needs to be able to answer the challenge on port 80. For web server without a LB, that means you just run the script and it generates the file that needs served up on 80.
With more than one web server you need to be able to server that file up on any instance that might get hit when the challenge request comes in.
For some, DNS might be an easier way to prove domain ownership, but we have clients who control their DNS. Doing it all on the web means it is 100% in our hands.