The question I have is how would a domain admin include a custom SSL certificate of their own?
One of the reasons that SSL certificates are managed at the System level is because custom or third party SSL certificates need to be installed or copied to specific directories in the server itself. Even when SmarterMail manages its certificates, it has to generate them to the same location. The Windows side of things has to utilizes the Centralized Certificate Store for our automatic certificates to work and this requires setup on the server itself.
Are you thinking a Domain admin should have the ability to disable SSL certificates for their own domain if the System admin allows it?
We have mitigations in place so our Let's Encrypt certificates can be generated without issue. There is also room to potentially include other Certificate Authorities in the future in case a client prefers one over another.
Jereming Chen
System/Network Administrator
SmarterTools Inc.
www.smartertools.com