5 ms·
Slightly off-topic: what's a good way to handle cases such as this where you have a wildcard certificate? I'll be getting a wildcard certificate for a project
by webignition 13y ago
Slightly off-topic: what's a good way to handle cases such as this where you have a wildcard certificate?
I'll be getting a wildcard certificate for a project and, never having used one before, I had assumed the certificate would be valid for an entire domain.
I understand from this situation that a wildcard certificate is relevant only to https://*.example.com https://*.example.com and not the subdomainless https://example.com https://example.com.
Assuming that to be the case, is having a wildcard certificate for *.example.com and a second certificate for example.com the solution? It'd be nice to have the entire domain covered by a wildcard certificate and not just all subdomains.
- phlo 13y agoNot all that off-topic. For your example, you should get a certificate made out to ("Subject CN") example.com or * .example.com, then list both the wildcard and the subdomainless entry as Subject Alternative Names. Bing is doing something similar (see https://news.ycombinator.com/item?id=5576271 https://news.ycombinator.com/item?id=5576271), but they appear to have forgotten to list the plain domain.
- klapinat0r 13y agoTypically a certificate issuer will grant you both when you buy a wildcard one. This can be achieved via SAN (alternative names): http://en.wikipedia.org/wiki/Wildcard_certificate#Limitation http://en.wikipedia.org/wiki/Wildcard_certificate#Limitation
- vsync 13y agoComodo's been good to me in this regard. Incidentally, beware of RapidSSL and their "free www." SAN; they only grant it in certain specific and undocumented circumstances.
- andygambles 13y agoWith RapidSSL if you order a cert for www.domain.com then it will also cover domain.com. But if you order a cert for domain.com or sub.domain.com then it will NOT secure the www.domain.com. So basically make sure your CSR request is for www.domain.com if you want to also secure the root domain.
- vsync 13y agoBizarrely, this only works for second-level domains however, and isn't disclosed in advance. Really, CAs shouldn't be throwing in "free bonus" SANs without customer authorization ever. It would be much better to have a place to enter the SANs, or a checkbox asking if I want "www." as well, or to apply to the parent also, or whatever. That would also make the process more apparent to the user in addition to being more secure.
- jimbobimbo 13y agoDepends on the type of cert. There're EV SSL certificates that do not allow wildcards, for example.