Currently, there isn't any TLS certificate for the fallback vhosts.
Plan is to set up wildcard certificates and revisit D2227.
Currently, there isn't any TLS certificate for the fallback vhosts.
Plan is to set up wildcard certificates and revisit D2227.
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Open | None | T1602 Provision ACME DNS credentials for core domains on each servers | |||
Open | None | T1599 Install TLS wildcard certificates for nginx fallback vhost |
Done manually for testing on Dwellers, but this creates the question about how to manage the wildcard certificates: should we share account and provision them in the acme config files on each server? does acme would follow several cname with contradictory information?
Really blocked by T1602 if we want to have this on any server without copying private keys around.