|
|
|
|
|
by mdhardeman
3085 days ago
|
|
But if you're a web post with 10k+ users, what's the problem with the HTTP-01 challenge? You just allow .well-known/* to be passed on to reflect the challenge responses you've generated for the client, while 301 redirecting everything else to their https:// site. I'm confused how that would be harder for a web host at that scale? EDIT: I get people trying to run a server off their cable modem / rtr public IP, and 80 might be taken by something other than the target the port forward for 443 is going to -- and that's a problem for those use cases -- but that kind of concern wouldn't exist in a significant hosting infrastructure. |
|
after that it could actually just put the cert into that store again and reload all public facing webservers