Hacker News new | past | comments | ask | show | jobs | submit login

Isn't it technically valid to issue a cert with (star).domain.com, (star).(star).domain.com, (star).(star).(star).domain.com, etc...?



No you can only have a single wildcard per domain listed in a cert.


And only as the leftmost component, that is, (star).example.com is valid, foo.(star).example.com is not.


You can technically create them, but IIRC browsers don't trust them.


And creating/signing them is a violation of the CAB Forum Baseline requirements.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: