Hacker News new | ask | show | jobs
by splitrocket 3299 days ago
TL;DR Security risk to utility tradeoff doesn't make sense.

Cert acquisition for new domains should be so lightweight that the API should meet most needs. If you hit the rate limit for new subdomains, buy a wildcard cert.

Risk: google.com------------------x.mydomain.com Etc.

Domain specific certainly allow for easier audit and revocation.

1 comments

If you hit the rate limit for new subdomains, buy a wildcard cert.

Going from $0 to $200 is quite a big step though.