Yep. But if using same private CA you may as well just use the same server cert on each box too. Then they could be just cloned configs, controlled by puppet, pulled from git...whatever. alan