🔒 It works, end to end.

You reached this page over a real Let's Encrypt certificate on projectsigma.digitalstronghold.com.

internet :443 → certd (ACME + relay, PROXY v2) → Caddy :8443 (TLS termination, static file) → this HTML.

certd owns 443 and issued/renews the cert; Caddy terminates TLS with the published cert and served this file. The real client IP was carried across the hop via PROXY protocol.