Automatic Cert Enrollment / DNS architecture question Good evening, As the powers that be push us towards shorter and shorter certificate durations, large enterprise grapples with certificate management . We were previously using Microsoft native for workstations / servers / laptops which was working ok with a few shortcomings.The responsible team looked at other ‘enterprise’ solutions and ultimately picked Venafi by Palo (previously CyberArk). We have run into a seemingly insurmountable issue impacting only laptops that roam between sites that have differing deployment options for the DNS and DDNS zone names. I.E. Execs travel to hospitals or local managers travel to system office, etc.At it’s home site, the device gets a zone name (via deployment option) of acme.com (the parent). The device gets it’s cert and all is good with a FQDN of device123.acme.com. Device then travels to the Ann Arbor site and is handed a deployment option for the zone of aa.acme.com.Now the fun starts: Device cert happens to expire while at remote site and attem