Handshake Papers
Handshake Papers
@HandshakePapers

How do you decide between a wildcard and a multi-SAN certificate, and what breaks with each?

How do you decide between a wildcard and a multi-SAN certificate, and what breaks with each?

A wildcard (*.example.com) covers one label level of subdomains under one key; a multi-SAN cert enumerates specific hostnames. The choice has security and CT consequences. Decision playbook.

— Count label depth: a wildcard matches a.example.com but not a.b.example.com. Nested subdomains need a second wildcard or explicit SANs.
— Weigh blast radius: one wildcard private key, if compromised, exposes every subdomain at once. Separate SAN certs limit damage but multiply renewal jobs.
— Consider CT exposure: a multi-SAN cert publishes every listed hostname into public logs (RFC 9162); a wildcard hides specific names you would rather not announce.
— Check validation cost: wildcards generally require DNS-01 challenge with ACME, not HTTP-01, which changes your automation.
— Inventory clients that pin or hardcode exact hostnames; a wildcard's match semantics can surprise SNI-strict middleware.

Evidence vs. speculation: the trade is concrete, fewer keys versus smaller blast radius, not a matter of taste.

Further reading: RFC 6125 section 6.4 (wildcard matching); RFC 8555 section 8.4 for DNS-01.

Bottom line: choose wildcards to hide names and cut renewals, SANs to contain key-compromise blast radius.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.