SSL Multilevel Subdomain Wildcard

Attrachii picture Attrachii · Nov 4, 2014 · Viewed 38k times · Source

I bought a wildcard certificate for *.example.com. Now, I have to secure *.subdomain.example.com. Is it possible to create a sub-certificate for my wildcard-certificate?

If it is, how I can do this?

Answer

Steffen Ullrich picture Steffen Ullrich · Nov 4, 2014

No, it is not possible. A wildcard inside a name only reflects a single label and the wildcard can only be leftmost. Thus *.*.example.org or www.*.example.org are not possible. And *.example.org will neither match example.org nor www.subdomain.example.org, only subdomain.example.org.

But you can have multiple wildcard names inside the same certificate, that is you can have *.example.org and *.subdomain.example.org inside the same certificate.