I would recommend fronting Espo with a reverse proxy that does TLS termination and takes care of renewing certificates, especially if you use an ACME-enabled...