Hacker News new | ask | show | jobs
by blibble 972 days ago
you could, but unfortunately the LE certs have a very short lifetime, and renewals are a thing

so you need a master server to handle the renewals, periodic sync, and to handle the case when the master goes away

this would be considerably more complicated than having a second independent certificate (assuming you've automated the entire frontend provisioning process)

1 comments

Did that, can confirm.

For other more sensible reasons but still.