# Create certificate for domain contain alot of subdomain

**URL:** <https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337>\
**Category:** Help\
**Created:** [June 14, 2018, 11:21am UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337 "2018-06-14T11:21:41Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 14, 2018, 11:21am UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/1 "2018-06-14T11:21:41Z")

</div>

If i have Domain [xxxx.co.uk](http://xxxx.co.uk) and this domain contain some subdomains like  
[A1.xxxx.co.uk](http://A1.xxxx.co.uk) , [B1.xxxx.co.uk](http://B1.xxxx.co.uk), [C1.xxxx.co.uk](http://C1.xxxx.co.uk), .....  
how can i create this cert ? via below command, right?

> certbot certonly -d "\*.xxxx.co.uk" -d [xxxx.co.uk](http://xxxx.co.uk)

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 14, 2018, 11:31am UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/2 "2018-06-14T11:31:24Z")

</div>

Hello @amna

> [@amna](#):
>
> certbot certonly -d “\*.xxxx.co.uk” -d [xxxx.co.uk](http://xxxx.co.uk)

that creates a wildcard-certificate with two entries - \*.xxx.co.uk and [xxx.co.uk](http://xxx.co.uk)

Do you want this or do you want 10 explicit certificates

[a1.xxx.co.uk](http://a1.xxx.co.uk)  
[b1.xxx.co.uk](http://b1.xxx.co.uk)

There are different options with different consequences to use the certificate.

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 14, 2018, 11:44am UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/3 "2018-06-14T11:44:34Z")

</div>

Hi @JuergenAuer ,  
thanks alot for your quick replay, as far as i know one certificate contain 100 names. i’d like to know how to create certificate for main domain [xxxx.co.uk](http://xxxx.co.uk) so i can create certificate to sub domain as name under main domain setificate not a new certificate?

my question with anther meaning?

1. if i want to create wildcard certificate, should i put all sub-domains or can i put \*
2. if i should add all sub-domains, if i want to add new sub-domain after first creation, this will consider new cert or will consider sub cert for main domain

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 14, 2018, 3:05pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/4 "2018-06-14T15:05:57Z")

</div>

> [@amna](#):
>
> 1. if i want to create wildcard certificate, should i put all sub-domains or can i put \*
> 2. if i should add all sub-domains, if i want to add new sub-domain after first creation, this will consider new cert or will consider sub cert for main domain

1. You can create a certificate with \*.example.com and [example.com](http://example.com). So you need not to list all subdomains in one certificate.

2. You would need a new certificate with this name.

I am using also a \*.example.com - certificate. It's easy, I can add a new subdomain, I don't need to create a new certificate.

But: Wildcard-certificates require ACME-v2, available since ~~ 03 / 2018. So check if your certbot is updated. And: dns-01 is required, so you have to add two dns-entries with the same name \_acme-challenge, one with the \*-hash, one with the hash of [example.com](http://example.com)

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 20, 2018, 12:41pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/5 "2018-06-20T12:41:07Z")

</div>

Hi JuergenAuer,  
how to set DNs entry to \*.example.com and [exmaple.com](http://exmaple.com). sorry for my bad question but in my case every vhost may be point to different ip for example  
[A1.example.com](http://A1.example.com) locat on server1 so in DNS entry [A1.exapmle.com](http://A1.exapmle.com) point to server1\_IP  
[A2.example.com](http://A2.example.com) locat on server2 so in DNS entry [A2.exapmle.com](http://A2.exapmle.com) point to server2\_IP  
[A3.example.com](http://A3.example.com) locat on server3 so in DNS entry [A3.exapmle.com](http://A3.exapmle.com) point to server3\_IP  
[A4.example.com](http://A4.example.com) locat on server4 so in DNS entry [A4.exapmle.com](http://A4.exapmle.com) point to server4\_IP  
[A5.example.com](http://A5.example.com) locat on server5 so in DNS entry [A5.exapmle.com](http://A5.exapmle.com) point to server5\_IP

and so on …

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 20, 2018, 1:37pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/6 "2018-06-20T13:37:48Z")

</div>

> [@amna](#):
>
> [A1.example.com](http://A1.example.com) locat on server1 so in DNS entry [A1.exapmle.com](http://A1.exapmle.com) point to server1\_IP  
> [A2.example.com](http://A2.example.com) locat on server2 so in DNS entry [A2.exapmle.com](http://A2.exapmle.com) point to server2\_IP  
> [A3.example.com](http://A3.example.com) locat on server3 so in DNS entry [A3.exapmle.com](http://A3.exapmle.com) point to server3\_IP  
> [A4.example.com](http://A4.example.com) locat on server4 so in DNS entry [A4.exapmle.com](http://A4.exapmle.com) point to server4\_IP  
> [A5.example.com](http://A5.example.com) locat on server5 so in DNS entry [A5.exapmle.com](http://A5.exapmle.com) point to server5\_IP

The IP-addresses of your subdomains are irrelevant.

If you want to get a \*.example.com + [example.com](http://example.com) - certificate (with two alternate names), you have to create two txt-entries.

\_acme-challenge.example.com

with two different values.

Depending on your DNS-hoster, you may only create two entries

\_acme-challenge

because the .example.com is added automatic. And the two values - Certbot may show these.

First use the staging system and create a certificate \*.example.com (without [example.com](http://example.com)).

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 20, 2018, 2:07pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/7 "2018-06-20T14:07:01Z")

</div>

sorry didn’t get your point, can you plz provide me example

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 20, 2018, 2:54pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/8 "2018-06-20T14:54:59Z")

</div>

> [@amna](#):
>
> sorry didn't get your point, can you plz provide me example

Use your first command. But use the test/stage-system. There is a Certbot-option to use the testsystem, but I don't use certbot.

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 21, 2018, 11:39am UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/9 "2018-06-21T11:39:25Z")

</div>

@JuergenAuer  
Let me clarify what i understood, i can install wildcard certificate by the one of the below  
Option 1  
git clone [https://github.com/Neilpang/acme.sh.git](https://github.com/Neilpang/acme.sh.git)  
cd ./acme.sh  
./acme.sh --install  
acme.sh --issue -d \*.example.com --dns --force (during run this step will show me message to set DNS entry, should i set as below or should i put IP of server " i can’t put specific IP as each vhost point to different IP server"  
TXT record \_acme-challenge  
value : “…” )

Option2  
certbot -d \*.example.com   
–manual   
–preferred-challenges   
dns certonly   
–server [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)  
(during run this step will show me message to set DNS entry, should i set as below or should i put IP of server " i can’t put specific IP as each vhost point to different IP server"  
TXT record \_acme-challenge  
value : “…” )

please confirm if this is correct specially DNS entry part

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 21, 2018, 1:18pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/10 "2018-06-21T13:18:03Z")

</div>

> [@amna](#):
>
> during run this step will show me message to set DNS entry, should i set as below or should i put IP of server " i can’t put specific IP as each vhost point to different IP server

I don't understand this. DNS - txt-entries don't use the ip-address.

And there is no global way, that depends of your dns-provider. My dns-provider has a menu (grouped by domain).

 ![DNS-Entry](https://global.discourse-cdn.com/letsencrypt/original/3X/6/e/6e92cc0c2d5869806409935b86d773461fda3164.png)

This creates a valid entry for \_acme-challenge.mydomain.de

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 27, 2018, 12:37pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/11 "2018-06-27T12:37:51Z")

</div>

Hi @JuergenAuer,  
i have used the below command to issue the wildcard certificate and set txt DNS entry for this domain  
./acme.sh --issue -d \*.example.com --dns --yes-I-know-dns-manual-mode-enough-go-ahead-please

Now i want to set the ssl vhost for each domain but i am not sure how?, as far as i know i should do the below

1. copy csr, key.chain to server1,server2,server3,… (any servers that i have vhost with domain \*.example.com) then configure ssl vhost file.  
" should i copy certificate from the server that i have installed acme.sh in or should i install acme.sh in all servers"

Another questions related to renew:  
can i renew wildcard certificate via the below cron job  
./acme.sh --issue -d \*.example.com --dns --yes-I-know-dns-manual-mode-enough-go-ahead-please --renew --force

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [June 27, 2018, 2:50pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/12 "2018-06-27T14:50:37Z")

</div>

> [@amna](#):
>
> Now i want to set the ssl vhost for each domain but i am not sure how?

That depends on your server software.

> [@amna](#):
>
> can i renew wildcard certificate via the below cron job

I don't use acme.sh and don't know the options.

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [June 27, 2018, 10:14pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/13 "2018-06-27T22:14:41Z")

</div>

> [@amna](#):
>
> can i renew wildcard certificate via the below cron job  
> ./acme.sh --issue -d \*.example.com --dns --yes-I-know-dns-manual-mode-enough-go-ahead-please --renew --force

No, because it will require manual interaction each time. And you don't want --force in a cron job, as you'll blow the rate limits pretty quickly.

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [June 28, 2018, 2:02pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/14 "2018-06-28T14:02:28Z")

</div>

@danb35  
what do you mean manual interaction? you mean every time that i renew certificate, i should change txt DNS entry

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [June 28, 2018, 2:40pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/15 "2018-06-28T14:40:39Z")

</div>

> [@amna](#):
>
> what do you mean manual interaction? you mean every time that i renew certificate, i should change txt DNS entry

Every time you renew the certificate, you **have to** change the `TXT` entry.

(Unless you have validated the name recently, but then you'd have no reason to renew.)

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [June 28, 2018, 7:21pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/16 "2018-06-28T19:21:25Z")

</div>

> [@amna](#):
>
> what do you mean manual interaction? you mean every time that i renew certificate, i should change txt DNS entry

What @mnordhoff said, and that you'll have to do it manually. And you're (incorrectly, apparently) telling acme.sh you understand that when you use the "--yes-I-know-dns-manual-mode-enough-go-ahead-please" flag. If you want automatic renewal (which you should), you need to be using a DNS host with a supported API so that the TXT records can be updated by the script.

---

<div class="post-metadata">

**Author:** ![amna](https://avatars.discourse-cdn.com/v4/letter/a/47e85d/32.png) [@amna](https://community.letsencrypt.org/u/amna)\
**Post date:** [July 10, 2018, 1:48pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/17 "2018-07-10T13:48:35Z")

</div>

@danb35  
thanks alot for your reply so i should enable api call for DNS host( i use godaddy " godaddy API" ) then write script to automatic change txt record

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [July 10, 2018, 1:52pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/18 "2018-07-10T13:52:02Z")

</div>

> [@amna](#):
>
> then write script to automatic change txt record

If you're using Godaddy for your DNS, you don't need to write anything; acme.sh already supports the Godaddy API:

> <https://github.com/acmesh-official/acme.sh/tree/master/dnsapi#4-use-godaddycom-domain-api-to-automatically-issue-cert>
>
> //github.com/acmesh-official/acme.sh/tree/master/dnsapi

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [August 9, 2018, 1:52pm UTC](https://community.letsencrypt.org/t/create-certificate-for-domain-contain-alot-of-subdomain/64337/19 "2018-08-09T13:52:03Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
