Hacker News new | ask | show | jobs
by tailspin2019 1644 days ago
I use wildcard LetsEncrypt certs for securing internal stuff which seems to solve this particular issue.

Something like *.internal.mydomain.com - so that’s all that would appear in transparency logs.

I guess this means you have to manage your own internal DNS mapping to your Tailscale IPs though rather than using Tailscale’s convenience split-DNS.