Certs for subdomains without the domain owner's permission

I’ve seen certs’ common-names with wildcards like “*.asite.com”. But I suppose that only applies to the particular cert and can’t override whatever subdomain certs there may be.