I.e. not using Lets Encrypt. Or using DNS based Lets Encrypt - I'm interested in running this inside the firewall.