<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body text="#000000" bgcolor="#FFFFFF">
On 01.04.18 09:58, Michael Stauber wrote:<br>
<blockquote type="cite"
cite="mid:b88039b9-b363-40b6-c389-6b7fcb1261c0@blueonyx.it">
<pre wrap="">Hi Meaulnes,
</pre>
<blockquote type="cite">
<pre wrap="">Lately, I got an e-mail from Let's Encrypt saying that they came out with the wildcard certificates. Do you think you could implement those?
</pre>
</blockquote>
<pre wrap="">See [BlueOnyx:21846] where I mentioned it.</pre>
</blockquote>
<p>I apologize, I missed that one...</p>
<blockquote type="cite"
cite="mid:b88039b9-b363-40b6-c389-6b7fcb1261c0@blueonyx.it">
<pre wrap="">In reality the wildcard certs aren't that useful on a BlueOnyx if you think about it. You can already have (almost) whatever alias you want included in the validity of the cert for a Vsite. As long as it points to that Vsite. And it costs nothing, so you can have as many as you like wherever you like.</pre>
</blockquote>
<p>sorry, I don't get it. What do you mean with an alias for the
vsite? The LE certificate is valid for <a class="moz-txt-link-abbreviated" href="http://www.mydomain.tld">www.mydomain.tld</a>, right? If
I want additional certificates for, say, mail.mydomain.tld and
<a class="moz-txt-link-abbreviated" href="ftp://ftp.mydomain.tld">ftp.mydomain.tld</a>, how do I do this?</p>
<p>If I go to Site Management > <a class="moz-txt-link-abbreviated" href="http://www.mydomain.tld">www.mydomain.tld</a> > SSL > <nobr>[<u>
^ 'Let's Encrypt!' </u>]</nobr> I can <nobr>[<u> Request or
Renew Certificate </u>]</nobr> but it isn't possible to add
any subdomains...</p>
<p>Thank you and best regards</p>
<p>Meaulnes Legler <br>
Zurich, Switzerland<br>
+41 44 2601660<br>
</p>
<br>
<p> </p>
<blockquote type="cite"
cite="mid:b88039b9-b363-40b6-c389-6b7fcb1261c0@blueonyx.it">
<pre wrap="">The cert validity for the wildcards is only 90 days as well.
So do you really want to set up a wildcard LE-cert on one Vsite and then
export and re-import that cert manually to wherever it's needed? And
repeat these manual steps every 60-90 days? It sort of defeats the
purpose of having auto-renewals if you can't effectively use them for
wildcard certs as well.
</pre>
</blockquote>
<br>
</body>
</html>