▲ | xg15 2 days ago | |||||||||||||||||||||||||
> But then you have to redistribute the cert from that single server to all the others. Wouldn't you have to do that anyway? Or is the idea that each server requests and renews a separate cert for itself? That sounds as if you'd have to watch out for multiple servers stepping on each other's toes during the DNS-01 challenge, if there is ever a situation where two or more servers want to renew their cert at the same time. | ||||||||||||||||||||||||||
▲ | cpach 2 days ago | parent [-] | |||||||||||||||||||||||||
Yup. There’s an RFC draft that addresses this dilemma. https://datatracker.ietf.org/doc/draft-ietf-acme-dns-account... | ||||||||||||||||||||||||||
|