Search code examples
sslssl-certificatesubdomainwildcard

Would a wildcard SSL Certificate work without a sub-domain?


We have to update our SSL certificate for an other year with a new COMODORS certificate.

We've had a old certificate (GeoTrust) with *.domain.ch which is correct from the naming aspect but expired from the date.

Now we've falsely made one with *domain.ch without the first dot. This should be a wildchart certificate for our domain.ch. Will this work or can this be the problem for server not starting after this SSL certificate update?


Solution

  • No it will not work. This certificate will match against wwwdomain.ch but not www.domain.ch. But, no public CA should issue such a certificate in the first place since you could this way impersonate foo-domain.ch etc, i.e. domains which don't belong to you.