I find the configuration at server level on the automatic generation of certificates incorrect.
it is a setting that ends up considering all domains the same, and all with the same personalized hostnames
In my opinion it should be moved to domain level. Each domain should have the option to enable/disable automatic certificate generation and its custom hostnames.
obviously inherited from domain default
And then I don't really understand this fallback thing.
If I issued a personalized certificate to a customer, for example
mail.customers.tld and he connects to his client, if the sni is not activated and he switches to the fallback certificate this will be a certificate for my server name i.e. mail.myserver.tld so he would tell me that the certificate is incorrect.
Sabatino Traini
Chief Information Officer