<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Let&#39;s Encrypt on ST2 Projects</title>
    <link>https://st2projects.com/tags/lets-encrypt/</link>
    <description>Recent content in Let&#39;s Encrypt on ST2 Projects</description>
    <image>
      <title>ST2 Projects</title>
      <url>https://st2projects.com/post-cover.png</url>
      <link>https://st2projects.com/post-cover.png</link>
    </image>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 19 Jan 2022 10:37:53 +0000</lastBuildDate>
    <atom:link href="https://st2projects.com/tags/lets-encrypt/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Internal Lets Encrypt</title>
      <link>https://st2projects.com/posts/internal-lets-encrypt/</link>
      <pubDate>Wed, 19 Jan 2022 10:37:53 +0000</pubDate>
      <guid>https://st2projects.com/posts/internal-lets-encrypt/</guid>
      <description>&lt;h1 id=&#34;internal-lets-encrypt-certificates&#34;&gt;Internal Let&amp;rsquo;s Encrypt Certificates&lt;/h1&gt;
&lt;p&gt;Here are some thoughts and ideas on how I have lets encrypt certificates deployed to home &lt;em&gt;infrastructure&lt;/em&gt; &amp;hellip;&lt;/p&gt;
&lt;p&gt;At a high level , my setup assigns a hostname based subdomain for each internal host.&lt;/p&gt;
&lt;p&gt;E.G. If my registered domain is &lt;code&gt;example.com&lt;/code&gt; and my host is &lt;code&gt;host1&lt;/code&gt; then I will generate a cert for &lt;code&gt;host1.example.com&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Let&amp;rsquo;s encrypt supports wildcards, you could use a wildcard if you wanted to. I didn&amp;rsquo;t like the idea of every internal host using the same keypair.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
