|
|
|
|
|
by zaroth
3529 days ago
|
|
If you are creating a new account key with a new authz, but the old account key still gives you access to renewal certs, that IMO is absolutely a bug. The authz should be tied to the { domain, account_key } tuple, not just the { domain }. Can anyone confirm? |
|
I have multiple servers that serve { domain } in dns round-robin. Each of them has a unique account key, but they also each issue certs for the same domain.
This is a totally normal and valid use-case, and allowing only a single account key for a domain at a time would ruin it.