From a7d859681f5508a829115376d9dd993f3f137321 Mon Sep 17 00:00:00 2001 From: Paul Buetow Date: Mon, 3 Aug 2026 10:27:49 +0300 Subject: frontends: give f3s hosts a standby. SAN instead of a separate cert f3s hosts don't get a distinct standby certificate/keypair; alias the primary cert's files under the standby name (relayd selects a keypair by SNI, so it needs matching filenames) and add standby. as a SAN on the primary cert. Every host now also gets www. as a SAN unconditionally, since public DNS publishes www for all of them. Co-Authored-By: Claude Sonnet 5 --- frontends/etc/relayd.conf.tpl | 2 -- 1 file changed, 2 deletions(-) (limited to 'frontends/etc/relayd.conf.tpl') diff --git a/frontends/etc/relayd.conf.tpl b/frontends/etc/relayd.conf.tpl index 8a53ed3..74a90f1 100644 --- a/frontends/etc/relayd.conf.tpl +++ b/frontends/etc/relayd.conf.tpl @@ -71,10 +71,8 @@ http protocol "https" { next if $host =~ /^(ipv4|ipv6)\./; -%> tls keypair <%= $host %> - <% unless (grep { $_ eq $host } @$f3s_hosts) { -%> tls keypair standby.<%= $host %> <% } -%> - <% } -%> tls keypair <%= $hostname.'.'.$domain -%> # Enable WebSocket support -- cgit v1.2.3