What is a wildcard SSL certificate?
How It Works
A wildcard SSL certificate is issued for a domain like *.example.com, where the asterisk represents any valid subdomain. For example, it would secure blog.example.com, shop.example.com, and mail.example.com, but not example.com itself unless that's also specified.
It simplifies management because you don't need separate certificates for each subdomain. However, it only covers one level of subdomains: *.example.com does not cover sub.blog.example.com. If you need multiple levels or multiple root domains, consider a multi-domain (SAN) certificate.
- Covers unlimited subdomains at one level.
- Does not cover the root domain unless explicitly added.
- Typically more expensive than standard single-domain certificates.
- Available as DV, OV, or EV validation levels.
- Can be used on multiple servers, but the private key must be shared.
When to Use It
Wildcard certificates are cost-effective for organizations with many subdomains, like SaaS platforms or large e-commerce sites. They also simplify administration: when you add a new subdomain, you don't need to buy or install a new certificate.
However, if you have subdomains hosted on different servers with different security needs, a wildcard might not be ideal because the same private key is used everywhere. In that case, separate certificates offer better isolation.
Common mistakes
- Assuming a wildcard covers the root domain (example.com) without explicitly including it.
- Thinking it covers multiple levels of subdomains (e.g., *.example.com does not cover a.b.example.com).
- Using a wildcard on shared hosting where other users might access the private key, compromising security.
