Use a public key for the main webserver's TLSA record.