Wildcard request: Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA

That would obviously not be allowed because ownership on the internet starts with the second level, enforced by the fact that websites can only be visited with second-level domains (example.com). It simply wouldn't fly.

What might be doable is an additional syntax, one that can only apply for 3rd level or higher, f.e. **.foo.com or **.sub.foo.com