3 ms·
Yup. We use a lot of Let's Encrypt certs with domain validation via http-01 where our internal API can handle all the requests and validation without the end us
by geetfun 9y ago
Yup. We use a lot of Let's Encrypt certs with domain validation via http-01 where our internal API can handle all the requests and validation without the end user requiring any technical knowledge.
It seems they will evaluate other options, but it's hard to imagine they would use something as convenient as http-01 for wildcards as then it opens up the platform to major abuse.
- dopamean 9y agoHow would it open up the platform for abuse (serious quetion, not snark)? The CA we use to get wildcard certs for our customers uses a challenge process very similar to LE's http-01.