# Wildcard Certificates Coming January 2018

**URL:** <https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567>\
**Category:** Issuance Policy\
**Created:** [July 6, 2017, 3:38pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567 "2017-07-06T15:38:17Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![prometheanfire](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/prometheanfire/32/14659_2.png) [@prometheanfire](https://community.letsencrypt.org/u/prometheanfire)\
**Post date:** [July 7, 2017, 6:24pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/43 "2017-07-07T18:24:35Z")

</div>

A san cert for the following works (I used to have one like the following)

```
*.sub1.domain1.com
*.sub2.domain1.com
*.domain1.com
domain1.com
*.sub1.domain2.com
*.sub2.domain2.com
*.domain2.com
domain2.com

```

So, it can do multiple domains and do multiple wildcards in the cert but it cannot do one like the following.

`*.*.domain1.com`

I can provide the cert if you'd like proof

edit: blockquotes

---

<div class="post-metadata">

**Author:** ![jsha](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jsha/32/12_2.png) [@jsha](https://community.letsencrypt.org/u/jsha)\
**Post date:** [July 7, 2017, 7:04pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/44 "2017-07-07T19:04:58Z")

</div>

> [@YesThatAllen](#):
>
> Is support for \*.domainA.com and \*.domainB.com in the same certificate on the roadmap?

Yep, this will work the same was as `domainA.com` and `domainB.com` in the same certificate works today.

> [@Knight](#):
>
> Is it possible to use up to 100 // 50 domains (both \* and root)?

Yep.

> [@jtl](#):
>
> Will the staging server be updated so people can test wildcard certificates and the validation required?

Eventually, yes. We still need to do the implementation work. For now, if you want to try out the v2 API, you can try our testbed server, [Pebble](https://github.com/letsencrypt/pebble).

---

<div class="post-metadata">

**Author:** ![akaro](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/akaro/32/13619_2.png) [@akaro](https://community.letsencrypt.org/u/akaro)\
**Post date:** [July 8, 2017, 1:43am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/45 "2017-07-08T01:43:42Z")

</div>

yes, please at first for 180 days. hopefuully !!

---

<div class="post-metadata">

**Author:** ![jared.m](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jared.m/32/17871_2.png) [@jared.m](https://community.letsencrypt.org/u/jared.m)\
**Post date:** [July 8, 2017, 8:07am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/46 "2017-07-08T08:07:28Z")

</div>

I’m in no way related to Let’s Encrypt, but I believe the 90-day expiration was a very deliberate decision, and I wouldn’t expect it to change. I feel your pain, I’m stuck maintaining a cert on GoDaddy shared hosting for a nonprofit I support. This means I have to paste the cert into cPanel every few months because GoDaddy shared hosting doesn’t support automated renewals. It’s somewhat unpleasant, but even so, I appreciate the 90-day validity period. Maintaining that quarterly is a really small price to pay.

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [July 8, 2017, 6:23pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/47 "2017-07-08T18:23:24Z")

</div>

There is a very long thread about the certificate lifetime issue, starting back in 2015.

> [@Pros and cons of 90-day certificate lifetimes](https://community.letsencrypt.org/t/pros-and-cons-of-90-day-certificate-lifetimes/4621):
>
> […

Please take any discussions about that aspect over to that thread.

---

<div class="post-metadata">

**Author:** ![designa\_dot\_ws](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/designa_dot_ws/32/14783_2.png) [@designa\_dot\_ws](https://community.letsencrypt.org/u/designa_dot_ws)\
**Post date:** [July 12, 2017, 10:51pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/48 "2017-07-12T22:51:29Z")

</div>

Oh hot damn! That’s great news, great great great news in Let’s Encrypt secure socket layer developments!

---

<div class="post-metadata">

**Author:** ![schoen](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/schoen/32/79_2.png) [@schoen](https://community.letsencrypt.org/u/schoen)\
**Post date:** [July 12, 2017, 10:54pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/49 "2017-07-12T22:54:13Z")

</div>

Glad you’re excited about them! By next year, maybe we can think of them as transport layer security developments. 🙂

> **[Transport Layer Security | History and development](https://en.wikipedia.org/wiki/Transport_Layer_Security#History_and_development)**
>
> Early research efforts towards transport layer security included the Secure Network Programming (SNP) application programming interface (API), which in 1993 explored the approach of having a secure transport layer API closely resembling Berkeley sockets, to facilitate retrofitting pre-existing network applications with security measures.

---

<div class="post-metadata">

**Author:** ![designa\_dot\_ws](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/designa_dot_ws/32/14783_2.png) [@designa\_dot\_ws](https://community.letsencrypt.org/u/designa_dot_ws)\
**Post date:** [July 12, 2017, 11:10pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/50 "2017-07-12T23:10:11Z")

</div>

Nothing but the best for a faster, more secure world wide web!

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [July 16, 2017, 12:58am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/51 "2017-07-16T00:58:54Z")

</div>

this actually adds more work

if you choose a random subdomain you still have to create a DNS record for it so it can point to a web server to pass the HTTP challenge

so if you are going to update the DNS wouldn’t it be easier to do it once?

Andrei

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [July 16, 2017, 12:59am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/52 "2017-07-16T00:59:37Z")

</div>

this was discussed earlier on in the chain

---

<div class="post-metadata">

**Author:** ![BFeely](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BFeely](https://community.letsencrypt.org/u/BFeely)\
**Post date:** [July 16, 2017, 2:08am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/53 "2017-07-16T02:08:32Z")

</div>

Will ECDSA certificates be supported in wildcard at launch too?  
Also, is there any word about launching a full EC CA?

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [July 16, 2017, 2:18am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/54 "2017-07-16T02:18:00Z")

</div>

You can get EC Certificates from Let’s Encrypt currently

Are you talking about an EC Intermediate?

Andrei

---

<div class="post-metadata">

**Author:** ![BFeely](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BFeely](https://community.letsencrypt.org/u/BFeely)\
**Post date:** [July 16, 2017, 2:26am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/55 "2017-07-16T02:26:35Z")

</div>

First question is whether EC certificate support will continue with wildcard support.

Second question is in fact when EC intermediate/root will be rolled out.

---

<div class="post-metadata">

**Author:** ![pfg](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/pfg/32/1924_2.png) [@pfg](https://community.letsencrypt.org/u/pfg)\
**Post date:** [July 16, 2017, 1:23pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/56 "2017-07-16T13:23:38Z")

</div>

ECDSA support is unrelated to wildcard issuance. There is no reason why wildcards would be limited to RSA.

Dedicated ECDSA roots and intermediates are scheduled for “Before September 1, 2017”, according to the [Upcoming Features page](https://letsencrypt.org/upcoming-features/).

---

<div class="post-metadata">

**Author:** ![tdelmas](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/tdelmas/32/1866_2.png) [@tdelmas](https://community.letsencrypt.org/u/tdelmas)\
**Post date:** [July 16, 2017, 8:51pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/57 "2017-07-16T20:51:13Z")

</div>

Of course, DNS CAA issuewild will be respected, right?

---

<div class="post-metadata">

**Author:** ![FGasper](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/fgasper/32/18787_2.png) [@FGasper](https://community.letsencrypt.org/u/FGasper)\
**Post date:** [July 17, 2017, 6:09am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/58 "2017-07-17T06:09:10Z")

</div>

You create a wildcard DNS entry once, then use that to do whatever HTTP validation.

In a lot of contexts (e.g., shared web hosting) it’s much easier to manipulate a web server than DNS.

---

<div class="post-metadata">

**Author:** ![BFeely](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BFeely](https://community.letsencrypt.org/u/BFeely)\
**Post date:** [July 18, 2017, 7:39am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/59 "2017-07-18T07:39:25Z")

</div>

I see no reason why it shouldn’t as CAA operates at the domain name level, at the same level as all your other DNS records.

---

<div class="post-metadata">

**Author:** ![RamblingGeekUK](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ramblinggeekuk/32/280_2.png) [@RamblingGeekUK](https://community.letsencrypt.org/u/RamblingGeekUK)\
**Post date:** [August 9, 2017, 9:01am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/60 "2017-08-09T09:01:25Z")

</div>

Reading through the thread, will SAN be supported?

---

<div class="post-metadata">

**Author:** ![tialaramex](https://avatars.discourse-cdn.com/v4/letter/t/f08c70/32.png) [@tialaramex](https://community.letsencrypt.org/u/tialaramex)\
**Post date:** [August 9, 2017, 10:32am UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/61 "2017-08-09T10:32:31Z")

</div>

Although it’s often mistakenly thought of as an alias actually SANs (Subject Alternative Names) are a mandatory feature of all modern certificates in the Web PKI. So yes, as far as Let’s Encrypt is concerned a wildcard is just another SAN dnsName it will add to your cert if you prove control over the name and you will be able to have up to 100 of them in a cert or mix and match with ordinary fully qualified domain names.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [August 9, 2017, 1:11pm UTC](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567/62 "2017-08-09T13:11:28Z")

</div>

A post was split to a new topic: [ACME v2 Beta Access?](https://community.letsencrypt.org/t/acme-v2-beta-access/39819)

[Previous page](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567.md?page=2)

[Next page](https://community.letsencrypt.org/t/wildcard-certificates-coming-january-2018/37567.md?page=4)
