In the firewall/extra services screen under http and https provisioning settings there is a note that says: “It is NOT ADVISED to expose this port to the public internet, as SIP Secrets will be available to a knowledgeable attacker”. I totally understand this for http but what exactly is the risk if using https with valid cert, strong pwd, etc?
If you’re using strong Apache credentials, then the risk is very low. A suitably configured fail2ban (such as is done with System Admin) will block anyone attempting to brute force it.