Comment by wielebny

3 years ago

That's not true. You can validate domains using dns-01, without exposing hosts.

and even with HTTP challenge you don't have to expose the host directly, but e.g. can copy the challenge response to a public webserver from the internal host or from a coordinator server.