Thanks. That cools me down a lot. I believe, that if xyz.example.com points to an IP address, on that IP address it is no possible to fulfill the challange for the example.com or abc.example.com (not pointing to the same IP address), even with TLS-SNI method. If this is not the case, please let me know.