G'Day Mack
I am clearly out of my depth with that many subdomains, but is there a specific reason you need to use commercial SSL certs as opposed to free certs from a provider like Let's Encrypt?
[Ken] Good question well asked mate, no your ! out of your depth, sub-doms on this scale is scary for every1, we didn't want 2 have 2 create a txt for each & every SD remember there could be 200K ( so that means these SD wouldn't exist ) we are already using Round Robin DNS so then the question becomes how to resolve something that doesn't exist, except on the Go HTTP servers, so if you 'hack' a DNS client / server & allow for a wildcard resolution then the HTTP server takes care of spelling mistakes / typos eg [
Pengiun.7o.au...] instead of [
Penguin.7o.au...] - let me go off on a tangent here - you currently have to enter http:// because we have no SSLs, 7o is said 7Go but u don't type the G & 7 is the first # in all of Tasmania's (TAS) postcodes, which to you guys from USA is a zip code, but ours are only 4 digits '9999' not 5 digits so this is why Ogle SD design cant scale up in USA ATM without a fundamental re-design of the TLD 2o ( NSW ) , 3o ( VIC ) , 4o ( QLD ) , 5o ( SA ) , 6o ( WA ) ... this is just not going to work when Zips are like 90210 & we only have 10 'states'
[Ken] Short answer, this angel bought BC in '13 when they were 'free' so they are R$$H & we don't want to offer a cheap option to them ATM :)
[Ken] We need WAN aware investors, who are going to be Hyper Local & bring a large group of contacts from their state to the table, this is all part of our "brand before you build" philosophy - we call them State Go Guardians ( SGG ) - which I know is kind of 'creepy' but the CEO is my wife & 'she who must be obeyed' - so I'm happy for you guys to contact her & tell her you don't think this is professional etc. , I will stand at the door & make certain she doesn't escape while u give her a piece of your mind :)
I accept that free SSL's aren't as good as commercial ones, but it would keep web browsers happy and remove "insecure" warnings.
[Ken] We just want to get the "insecure" warning to go away, this system is designed to be used during a natural disaster, so we won't be using a login / pwd pair for any1 we need IT to be as simple as possible because the 'customer' will probably be under hugh pressure, but we need to feed the AI with "Yes I can smell the smoke from the bush fire", "Yes I can see the flames from the bush fire" , "Yes" my dog is hiding !
[Ken] We don't have earth quakes ( well almost ) in Oz, unlike in the USA, but I know from when I lived in Minnesota ( Little Apple ) that Dogs ( a mans best friend ) seem to know when they are about o 'hit', so we are looking to get local government to export their dog. registration DBs & we will turn that into Go Pages, this is why each page is less than 2mb & why they render so fast & we never need to archive our web servers. We currently use AI to mine Google Bus. Profile ( GBP ) for all of the text we have inside of the HTML so do we really need SSLs ?
I imagine you have a good reason for not wanting to go down this route, but it may be a solution (if only temporary)?
[Ken] We don't go live until 12 / 12 / 25 so everything is temp. ATM, just working thru. the incidents, so I will try some free SSL & try & find a down side, but we are already 'conning' the customers, because the Sub-dom ( TXT records ) will not exist in a DNS server, so IT seems crazy to them show them a key & pretend they are 'safe'
[Ken] Now you understand a little more about why Go Group is so confused, we don't even have a good name for the WAN that doesn't exist, absolutely not using Dark Web, maybe 'invisible web' , 'Oz only web' , 'JIT WAN' , "iWAN' these are some of the better ideas,
TIA
KSA