Could a feature be added to USG/ATPs where you can use a lets encrypt certificate for say SSLVPNs, and set it too auto renew every 90 days? So other vendors already support this.

  Zulgrib
    Zulgrib
    If the certificate hash changes all the time you cannot verify in a reliable way if there's a mitm attack. The correct way is to create your PKI.