Skip to content

How do you handle SSL certificates for internal services?

Dedicated Servers by hankels 5 replies 163 views
#1

SSL cert management is my sunday evening nightmare

Current split:

  • Private CA (step-ca) - 21 boxes, internal services only
  • Let's Encrypt DNS-01 - 18 boxes, anything that touches public
  • Ignore browser warnings - 13 boxes, legacy stuff I should migrate

Considering consolidating but the migration pain is real. What are you all doing? Is anyone actually paying for certs in 2026?

seedbox, NAS, tape, and three offsite
#2

Private CA.
One root.
Two intermediates.
Offline root.
Ansible deploys.
No browser trust.
Dont care.
Internal only.

#3
hankels said:
52 boxes

Private CA for internal (42%), Let's Encrypt DNS challenge for public-facing (38%), and a shameful 20% still on manual renewal because the owners won't give me API access to their DNS. Alert fatigue is real; I have 3 cert-related pages per week that are just "renew in 14 days."

436 days. reboot is surrender.
#4

I just use the dns challenge for everything now, even internal stuff. Set up a public subdomain pionting to 192.168.x.x, lets encrypt doesnt care. The validation only checks dns not routing. Runn a cron job and forget. You figure it out he says

#5

Thank you very much sir for making this poll. I made VPS last month with GreenCloudVPS, used Let's Encrypt sir, very easy. For internal I use self-signed sir, but browser warning is annoying. Maybe I try private CA sir, thank you bro

#6

Super hassle ang private CA, diba? Nag-setup ako ng step-ca before, sobrang complicated. Ngayon ginagamit ko lang Cloudflare origin certs sa nginx (https://www.cloudflare.com), super easy. Internal services ko naman walang public access. Mas ok ba private CA for many boxes?

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft