Skip to content

SSL for 50 subdomains: wildcard or individual?

Web Hosting by nate_pad 24 replies 1.5K views
#11

You can get multiple wildcard certs for the same domain from different CAs, or split by zone. But that's just more keys to manage.

Real talk: for 50+ dynamic subs, wildcard is the practical choice. Just lock down the server hard, use Hetzner's firewall, and store the key in their vault or at least not in your app repo.

Vienna represent btw.

#12

Yaml victim here. You people are talking about rate limits like they're hard walls. You can request increase from let's encrypt (https://letsencrypt.org) if you explain your use case. Takes a few days though. Did it in 2019 for a cluster, worked fine.

#13

I'm on Hetzner in Falkenstein and use their Load Balancer with managed SSL. Handles the wildcard for me, I never touch the private key directly. Costs a bit more but worth it for not having to think about this stuff.

#14

This.

9 #15

Hankels you said 40 subs on wildcard for resellers. Do your customers know they share a key? I'd want to know that as a customer. GDPR and all that maybe? Not sure just asking.

#16
tomhider said:
Do your customers know they share a key?

It's in my terms, yeah. "Shared infrastructure" covers it. These are small business sites, not banks. If someone needs dedicated everything I charge accordingly and we do individual certs.

GDPR doesn't mandate crypto isolation last I checked. It's about data processing, not TLS key architecture.

seedbox, NAS, tape, and three offsite
#17

In France I would check CNIL guidance on this. Shared key between tenants might fall under "mesures de securite appropriees" depending on what data you handle. Not saying it's forbidden, but I would document the risk analysis.

For my own stuff in Toulouse I use individual certs with acme.sh and OVH DNS. 30 subs, no rate limit issues because they don't all renew same week.

#18
Space25 said:
I'm on Hetzner in Falkenstein and use their Load Balancer with managed SSL.

That's actually a solid middle path. Hetzner manages the key in their infrastructure, not on your VPS. You still have shared-tenant risk if Hetzner gets breached, but that's a different threat model than your own server being compromised.

Costs what, 6 EUR base plus cert? Still cheaper than 50 individual cert management hours.

#19

Here in brazil hetzner is already expensive with euro conversion. 50 individual certs from let's encrypt is free but the automation work is not. I would go wildcard and spend time securing the server instead. Vou fazer isso no meu projeto também.

chill infrastructure for chill people 🦫
4 #20

Following this thread. Same situation, about 35 subs on DigitalOcean. Leaning wildcard now.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft