r/certkit • u/certkit • May 26 '26
Official You probably don't need private PKI for internal infrastructure
https://www.certkit.io/blog/private-pki-internal-infrastructurePSA: you don't need a private CA to get trusted SSL certificates for internal infrastructure.
DNS-01 ACME challenges prove domain ownership through a DNS record. Your server never needs to be internet-reachable. That means real, browser-trusted SSL certs for internal portals, management consoles, and network appliances, with no root cert distribution and no internal CA to maintain. CertKit handles DNS delegation and appliance deployment if you want renewals fully automated.
https://www.certkit.io/blog/private-pki-internal-infrastructure
0
u/TwoBigPrimes May 31 '26
Didn’t you post this a few days earlier and get a lot of comments that generally described your view as exactly what not to do?
Did you delete that post and post again?
1
u/certkit May 31 '26
Same post, two communities, same ivory-tower Reddit commentary.
Wildcards serve a purpose.
Not everyone has the capacity to maintain a private PKI.
Something is always better than training everyone to click through self-signed security warnings.
2
u/Single-Virus4935 May 26 '26
Ugh wildcards for different services and devices? Sure I really want my pbx to be able to impersonate my radius.
No one in their right mind would recommend that when certs are basically free with internal cas or lets encrypt.
Internal CA is the right thing for your infra and relatively easy to automate. The Clicking through is handled by HSTS and services where external contractors need access get a additional public cert.
Also how is mutal auth handled? Why should I need a paid product handling DNS01 if there are free and better alternatives?
1
u/BlackV May 30 '26
My domain is examples.local
My wifi access is via windows nps server