Jump to content

Tab Stop

Straight answers for everyday tech

Web, security and privacy

Cheap wildcard SSL certificates: where to get one

· 3 min read

Short answer

One wildcard certificate can cover every subdomain at one level of a domain. It is cheap to buy, sometimes free, and has a few limits worth knowing first.

A wildcard certificate is an SSL/TLS certificate issued for a name that starts with an asterisk, such as *.example.com. Browsers accept it for any single label in that position: www.example.com, shop.example.com, mail.example.com, and any subdomain added later without reissuing anything.

What it covers, and what it does not

The asterisk matches exactly one level. *.example.com does not cover api.eu.example.com; that needs its own certificate or a second wildcard for *.eu.example.com. The matching rules are set out in RFC 6125, section 6.4.3.

The bare domain example.com is not matched by the asterisk either. Most commercial wildcards add it as a second name at no charge; with a free certificate you request both names yourself.

Wildcards come in domain validation (DV) and organization validation (OV) versions only. Industry rules do not allow extended validation (EV) wildcards, so a business that wants EV must buy a certificate per hostname.

Why people use them

  • One certificate and one renewal date instead of a spreadsheet of separate certificates.
  • New subdomains are covered from the moment they exist.
  • Most paid wildcards allow installation on unlimited servers at no extra cost.
  • Subdomain names stay out of public view. Every publicly trusted certificate is recorded in Certificate Transparency logs that anyone can search, so separate certificates reveal names such as staging.example.com; a wildcard shows only *.example.com.

The trade-off is shared risk. The same private key sits on every server that uses the certificate, so a leak on one machine means revoking and replacing it everywhere. Sites that run subdomains on servers with different owners or security levels are better off with separate certificates.

Validity in 2021

Since September 1, 2020, browsers reject newly issued certificates valid for more than 398 days. Sellers still offer two- to five-year “subscriptions”, but those deliver a fresh certificate each year that has to be installed again. Compare prices per year, and set a reminder for each reissue, because the provider will not install the new certificate for you.

Renewal is where wildcards cause outages. One expired certificate takes down every subdomain at once, so it is worth monitoring the expiry date from outside, with the provider’s reminder emails going to an address someone actually reads.

How to get one

You generate a certificate signing request (CSR) on your server with *.example.com as the common name and send it to the provider. For DV wildcards, control of the domain is proved by email to an address such as admin@example.com or by a DNS record; the file-upload method used for single-name certificates does not work for wildcards. OV adds a check of the company’s registration, which takes one to a few days. Then install the certificate and intermediate chain on each server.

Where to get one

Let’s Encrypt (free)

The nonprofit certificate authority has issued wildcards since March 2018. Its FAQ states that wildcards require the DNS-01 challenge, meaning your ACME client must be able to create a TXT record, usually through your DNS provider’s API. Certificates last 90 days and are meant to renew automatically. Let’s Encrypt issues DV only and offers no warranty or site seal, which rarely matters to visitors.

Namecheap

The registrar resells Sectigo certificates under its own product names. PositiveSSL Wildcard is its cheapest DV option, EssentialSSL Wildcard is also DV, and PremiumSSL Wildcard is OV. It is a sensible choice for domains already registered there.

Sectigo brands and resellers

Sectigo is the certificate authority formerly called Comodo CA, renamed in 2018. Its wildcards are sold under Sectigo, PositiveSSL, EssentialSSL and InstantSSL names. ComodoSSLStore is a reseller specializing in these, and InstantSSL Wildcard is the OV version.

DigiCert brands: RapidSSL and Thawte

DigiCert owns the RapidSSL, GeoTrust and Thawte brands. RapidSSL Wildcard is a DV product issued within minutes, often the cheapest wildcard from a DigiCert root. Thawte Wildcard SSL is an OV certificate for companies that want their organization name in the certificate details. Resellers such as RapidSSLOnline and TheSSLStore sell both below the brands’ own list prices.

GoDaddy

GoDaddy issues its own wildcards, managed from the same dashboard as its domains and hosting, with 24/7 phone support. List prices are high, but it discounts heavily for the first year.

Gandi

The French registrar sells Sectigo-issued wildcards alongside its domains and hosting. It suits customers who already manage DNS at Gandi, since DNS validation is then a few clicks.

For a personal project or any server that can automate renewals, Let’s Encrypt removes the cost entirely. A paid wildcard earns its price when you need OV, a warranty, a long-lived manual install, or a support line to call when something breaks.