Wildcard — SSL certificates that cover subdomains

Wildcard certificates cover a main domain with all subdomains.

Wildcard certificates allow businesses to secure a main domain and an unlimited number of subdomains. A wildcard certificate can be a cost- and labor-saving SSL solution, especially for businesses that have many subdomains or frequently need new ones.

The wildcard name comes from the * character, which is often referred to as a wildcard in an IT context. For example, a wildcard certificate for *.example.com can cover test.example.com, mail.example.no, blog.example.no and so on.

Commfides offers wildcard solutions for two levels of security within SSL certificates:

  • DV (Domain Validation): Basic protection, ideal for smaller websites.
  • OV (Organization Validation): More secure solution that verifies your organization’s identity.

Wildcard certificates cannot be issued at EV level (Extended Validation), which is the highest security level for SSL. This is because EV certificates require the company to have full control over domains when they are issued, and this is not possible in principle since new domains can be added later.

Another limitation of wildcard certificates is that they only cover one level of subdomains. A certificate for *example.no covers test.example.no but not web.test.example.no. Nor can a wildcard certificate cover an additional main domain such as examples.no

Can be combined with SAN solutions

For businesses that need an even more flexible solution for multiple domains, SAN certificates or multi-domain certificates can be a good solution. SAN certificates can cover multiple top-level domains as well as specific subdomains under those domains.

It is also possible to combine SAN and Wildcard solutions: A wildcard domain can be added as a subdomain in a SAN solution under a main domain.

To order a wildcard certificate, a CSR file or Certificate Signing Request must be created, a request to the certificate issuer where the main domain is specified. The issuance process usually takes 1-3 days and the certificates must be renewed regularly.

Wildcard certificates are priced higher than regular domain certificates because of the flexibility they offer. However, for many organizations, the benefits of easier administration and the ability to add new subdomains as needed may outweigh the increased cost.

Skroll til toppen