Im hoping to avoid a DIY CA.
Currently I have a pihole and nginx proxy sending requests on my LAN for service.mydomain.com where they need to go.
In parallel I have each setup as a service on tailscale. I have DNS setup so service.mydomain.com points to the tailnet IP of that service.
I wish it were viable to CNAME to the tailnet URL and be done with it but it is not to be.
For other reasons I need to stick with one providers nameservers and they do not provide an API for DNS records so getting a wildcard cert via DNS-01 is not viable? Unless Im missing something which would be awesome.
I have a separate VPS at my disposal.
Any crafty ways to get a wildcard cert with this setup or possibly HTML challenges for each subdomain via the VPS to then use on the segregated server?
I would prefer not to open up 443 on the home net if possible.
Any and all creative solutions welcome..
Source: r/selfhosted · by /u/MistaKD