Comment by Parodper
4 hours ago
> Allowing user to just generate a domain for themselves
That's limited mostly by policy[1], the current PKI environment already allows delegating CA for a single domain.
[1] https://community.letsencrypt.org/t/sub-ca-with-wildcard-cer...
Last time I checked support for that on client side was pretty spotty