Hacker News new | ask | show | jobs
by ivlad 17 days ago
Or, just use IPv6 and host Internet services in a routable address. Then, use ACLs at web server / proxy / L7 lb level to allow acme-challenge unauthenticated but everything else authenticated.

Lets encrypt supports IPv6 for validation.