Said It Here

Deciding which hostname to use for a certificate

Unsure which hostname to include in a mail server TLS certificate when configuring MX records with CNAME redirection.

What the numbers show

Counted from the threads quoted below. How we count

  • The most recent one is from October 2026.
  • It is not one crowd: 3 people on Reddit and 1 on Stack Exchange ran into the same thing.

What people tried

Every workaround mentioned in the threads below. We haven’t tested any of them — and nobody here is claiming they worked.

  1. 1
    Configuring various candidate hostnames such as CNAME targets, PTR names, or HELO/EHLO names
  2. 2
    Moving location, OS, and hardware details to DNS subdomains or CMDB/inventory software instead of putting them in the hostname
  3. 3
    Using immutable static asset tag IDs or serial numbers for endpoint devices
  4. 4
    Naming hosts strictly by role, environment, and number (e.g., sql-prd01)
  5. 5
    Using fixed-width schema patterns with variable fields parsed by regex in Ansible

In their words

Unedited, grouped by where they were said, most upvoted first within each place, each linked to the thread it came from.

Server Fault1 person · January 2026

“I want to obtain a valid TLS certificate for an SMTP ( MX ) server, but I am unsure which hostname should be included in the certificate's CN/SAN.”source ↗

Tobia · Server Fault · 8 upvotes
r/sysadmin3 people · October 2026

“regret ever putting os or hardware type in the name, had a bunch of linux boxes that ended up running windows and it was just confusing.”source ↗

Hopeful-Horse7580 · r/sysadmin · 1 upvotes

“making the hostname reflect the location or some other variable that is subject to change is a pain.”source ↗

ryryrpm · r/sysadmin · 1 upvotes

“Trying to learn how naming standards are actually done in enterprise environments, and what holds up as things grow.”source ↗

LastBlueberry5224 · r/sysadmin

Where this came up

People with this problem also raised