Hey, I think almost everyone heard of the changes regarding the certificate renewal time. I don't want to be late to the party, therefore I am evaluating how to actually proceed with the automation.
I know that you can use ACME to actually retrieve/request the certificate, but that would be only possible if the DNS our company uses allows that DNS-challenge, right? Since wildcard certs (we use it) aren't able to be requested with http, we have to do the DNS-thing. What do you think would be the other options available in this case?
Afterwards, the certificate needs to be imported in our various services like NGINX, IIS, Java-Keystores etc.. I was thinking of Powershell, but is there a better solution?
How do you manage it? I would be glad to get some input from you. Tysm!
Source: r/sysadmin · by /u/ulxtii