logoalt Hacker News

bombcaryesterday at 3:38 PM3 repliesview on HN

If you somewhat want to avoid this, get a wildcard certificate (LE supports them: https://community.letsencrypt.org/t/acme-v2-production-envir...

Then all they know is the main domain, and you can somewhat hide in obscurity.


Replies

bityardyesterday at 5:24 PM

Yep, but this comes with a tradeoff: all of your services now have a valid key/cert for your whole domain, significantly increasing the blast radius if one service is compromised.

show 2 replies
vaultyesterday at 4:21 PM

Correct, that's what I did with caddy, which is now periodically renewing my wildcard certificate through a DNS-01 challenge.

show 1 reply
lysaceyesterday at 3:50 PM

Unfortunately they are a bit extra bothersome to automate (depending on your DNS provider/setup) because of the DNS CNAME-method validation requirement.

show 4 replies