The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
That's what I mean. But that still means additional configuration in every vhost. With TLS-SNI-01 it was completely transparent with zero additional configuration - I just had the certbot plugin automatically create and remove dummy standalone vhosts to serve the challenge certs.