Currently security sandboxing happens basically per Origin. Since schema and port is fix, and I don't want to force every user/potential-user/demo-user/anon to register a domain (so the LE rate limit doesn't apply, and nobody want's bloated 100 SAN certs).
I know the names, but rerolling a cert takes time, takes up resources, etc.
I know the names, but rerolling a cert takes time, takes up resources, etc.