3 ms·
Renewing any certificate that requires a manual import is not fun. Why are wildcard certs less fun to manually import than individual certificates?
by dfc 3y ago
Renewing any certificate that requires a manual import is not fun. Why are wildcard certs less fun to manually import than individual certificates?
- nullindividual 3y agoPresumably one purchases a wildcard for multiple distinct systems.
- dfc 3y agoUsing them like that never occurred to me. I was thinking multiple sites on one host or vanity hostnames: dfc.example.com / nullindividual.example.com. etc.
- nullindividual 3y agoUnless you're running some sort of automated system to churn out vanity host names (like an Azure or AWS would to provide you an OOTB URI), a UCC/SAN cert is a better choice. More restrictive is better than less restrictive when it comes to certificates.