the Postfix documentation on TLS advises against storing key and certificates in separate files because of possible race conditions during key rollover. It is rather complicated to follow this advice when using self-updating Let's Encrypt certificates, so how serious is the race condition issue?
In general, when does Postfix read new key/cert files without being reloaded or restarted?
Thanks, Jan
0 Answers