Handshake Papers
Handshake Papers
@HandshakePapers

Wildcard or multi-SAN certificate: which one minimizes your actual blast radius?

Wildcard or multi-SAN certificate: which one minimizes your actual blast radius?

When you cover many hostnames, do you reach for one wildcard or a list of Subject Alternative Names? The choice is a security-versus-operations tradeoff, and the security side is underappreciated.

A wildcard (*.example.com) matches any single-label subdomain with one certificate and one private key. Operationally elegant — new subdomains need no reissue — but the blast radius is total: one leaked key compromises every subdomain, and a wildcard cannot be scoped per service.

A multi-SAN certificate enumerates exact hostnames. Adding a host means reissuance, which is friction, but each certificate set is explicit, auditable in Certificate Transparency logs, and you can split keys across services to contain compromise.

Wildcards also do not span depth: *.example.com does not match a.b.example.com, a common misconfiguration.

— Use SANs when you want least-privilege, per-service key isolation.
— Use wildcards for sprawling, ephemeral subdomains where reissuance is impractical.
— Never share one wildcard key across trust boundaries.

Further reading: RFC 6125 §6.4 on wildcard matching; RFC 5280 on SANs.

Bottom line: wildcards optimize operations at the cost of a maximal blast radius; SANs optimize isolation at the cost of reissuance — match the choice to how much you fear key compromise.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.