Remix.run Logo
mcny 2 days ago

I thought the whole point of the acme client was that the private key never leaves my server to go to let's encrypt servers. Now yes, if I am using cloudflare tunnel, I understand the tls terminates at cloudflare and they can share with anyone but still it has to be a targeted operation, right? It isn't like cloudflare would simply share all the keys to the kingdom?

notpushkin 2 days ago | parent [-]

Yes. They could issue their own certificates, but we have CT to mitigate that, too.