Just for curiosity, what is the authentication method will be used in issuing wildcard certs? Some sort of DNS records?

The authentication will be via DNS challenge, quoting Let Encrypt’s announcement post: We will initially only support base domain validation via DNS for wildcard certificates, but may explore additional validation options over time.

