3 ms·
And you have two or more servers serving this domain you’re out of luck
by abcdefg12 1y ago
And you have two or more servers serving this domain you’re out of luck
- lmz 1y agoAnd this is different from DNS how exactly? The key and resulting cert still needs to be distributed among your servers no matter which method is used.
- cpach 1y agoWith dns-01, multiple servers could, independently of each other, fetch a certificate for the same set of hostnames. Not sure if it’s a good idea though.
- lmz 1y agoMultiple keys and certs for the same hostname? Will the CA even issue that?
- cpach 1y agoI guess it depends on the CA, but some do. Let’s Encrypt does, for example. I guess it’s useful for HA deployments, where load balancers might be spread out across multiple datacenters and stuff like that. NB that rate limits apply https://letsencrypt.org/docs/rate-limits/ https://letsencrypt.org/docs/rate-limits/
- account42 1y agoNot really, just forward .well-known/acme-challenge/* requests to a single server or otherwise make sure that the challenge responses are served from all instances.