Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks! This looks awesome. Can i automate it as well?

I have been toying a little with wildcard using certbot on my Ubuntu OpenVPN appliance, but was a bit unsuccessful at the moment.

Maybe i should just try and build a very tiny virtual sever that does nothing but spit out a wildcard domain certificate to some predefined destinations to have it used in anything that wants a certificate. Could be beneficial to a (large) infrastructure to have an always-ready certificate to use for free. Dunno if EV validation will uphold though.



For provider with DNS support, you can put it in a cron, and then create symlink or some copy step at the end of cron to copy private key and full chain to appropriate location of your web server.

I think acme.sh is the easiet to use in all of clients.


Thanks again. Everything works.

I've put my DNS to Cloudflare and after that the acme.sh was incredibly easy to implement thanks to their API implementations.

Also learned a valuble lesson: *.provider.com is not the same as provider.com :)




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: