|
|
|
|
|
by brewmarche
678 days ago
|
|
Probably most people would deem the risk negligible, but it’s still worth to mention it, since you should evaluate for yourself. Regarding the central machine: the certificate must not only be generated or fetched (which as you said probably will happen “at the center”) but also deployed to the individual services. If you don’t use a central gateway terminating TLS early the certificate will live on many machines, not just “at the center.” |
|
[1]: https://github.com/Sieboldianus/ssl_get