This would be a great feature. Configure a couple of hostnames you want certificates for, and then have the firewall automatically request/renew them with letsencrypt.org. This will save a lot of time, especially when using services that require a valid certificate such as SSTP VPN’s.
No, they are “certificats”, can be use on anything (firewall, mail, ftp, etc…). The only “problem” is that they are 90 days lifetime… so without ACME, you’ll have to update the cert manually each 3 month. Certs are actually working right now if you do install it manually.
also simple and neat ability to create and manage separate certs blacklists(including automated with scripts/scheduler from remote source oudate of it) “just in case” - would help a lot, too.