> one issue i've had with let's encrypt is trying to use it on private 
> subdomains on AWS.  iirc the system needs to have a public DNS entry as 
> well as access from the internet to work - i might be mistaken tho on 
> this...

I have LE certs for RFC 1918 addresses.  The DNS server I use to validate is a public DNS server, but where
you user the cert is not relevant.

