Definition
If you want to secure multiple wildcard domains and multiple levels of subdomains under one certificate, look no further than Multi-Domain Wildcard SSL certificates. It combines the features of two different SSL certificate types: Multi-Domain (SAN) certificates and Wildcard SSL certificates, offering a powerful and flexible security solution.
Multi-Domain Wildcard Certificates can secure both fully-qualified domain names and multiple wildcard domains within their SAN entries.
How Multi-Domain Wildcard SSL Certificates Work
Multi-Domain Wildcard SSL certificates work by allowing you to specify multiple domains in the Subject Alternative Name (SAN) extension and use wildcard notation (asterisk *) to cover unlimited subdomains for each specified domain.
For example, use Multi-Domain Wildcard SSL to Secure:
- Common Name: yourdomain.com
- SAN 1: *.youdomain.com
- SAN 2: *.mail.yourdomain.com
- SAN 3: *.example.com
The wildcard character (*) represents any single level of subdomain. For multi-level subdomains, you would need to add specific wildcard SAN entries (e.g., *.mail.yourdomain.com to cover dev.mail.yourdomain.com).
Key Technical Requirements
1. Common Name (CN) Requirement:
The Certificate Signing Request (CSR) must have a non-wildcard domain (FQDN) as the Common Name. The wildcard versions need to be included as SANs.
2. Domain Coverage:
Multi-Domain Wildcard SSL certificate allows you to secure and encrypt:
- FQDN (Fully Qualified Domain Names)
- Wildcard domains
- Multi-level Wildcard subdomains (e.g., *.mail.yourdomain.com)
While wildcard entries cover all subdomains at a specific level, they don’t automatically secure:
- The non-www versions of wildcard domains
- The wildcard version of the Common Name (unless specifically requested as a SAN)
- Multi-level subdomains beyond the specified wildcard level
Validation Levels Available
1. Domain Validation (DV): Thawte DV Multi-Domain Wildcard SSL
- Fastest issuance (minutes)
- Verifies domain ownership only
- Lower cost option
2. Organization Validation (OV): Thawte OV Multi-Domain Wildcard SSL
- Medium level verification (1-3 days)
- Verifies organization legitimacy
- Displays organization details in SSL certificate
- Higher trust level than DV