The edge obtains a certificate during the TLS handshake, but only for hostnames the control-plane authorizes via an O(1) 'ask' lookup. So a cert is only ever issued for a verified, known domain — no pre-provisioning, and renewals are automatic.
Ask questions and share what you're building with custom domains — DNS, automatic SSL, the reverse-proxy edge, self-hosting and the API. The Connect Domain community is here to help.
This question has been flagged
2
Views
Enjoying the discussion? Don't just read, join in!
Create an account today to enjoy exclusive features and engage with our awesome community!
Sign up