Skip to content

Stuck between one wildcard cert (*.vectel.nl) and a SAN cert with explicit subdomains

Wildcard covers any subdomain, but one cert shares private-key risk across everything. SAN (Subject Alternative Names) names explicitly which hosts are on it. For SMB with many ad-hoc subdomains wildcard wins, for strict security SAN wins.

Try this first

  1. 1For a small number of subdomains (3 to 10): a SAN cert is clearer and reduces blast radius on a key leak.
  2. 2For many or dynamic subdomains (preview deploys, customer-specific subdomains): wildcard is more practical, otherwise ACME rate limits hit daily.
  3. 3Wildcard covers only one level (*.vectel.nl, not *.dev.vectel.nl). For two levels you need two wildcards or a SAN.
  4. 4With wildcard: store the private key in a secrets manager with tight ACL, not spread across dev machines.
  5. 5For public websites: both wildcard and SAN are free via Let's Encrypt or ZeroSSL. EV certs are practically SAN-only.

When to bring us in

If you want a cert strategy that fits your deploy flow and risk profile, we can choose between wildcard, SAN or a mix.

See also

None of the above fits?

Describe your situation below. We pass your input plus the steps you already saw to our AI and return tailored next-step advice. If it's too risky to DIY, we'll say so.

Who are you?

For the AI question we need your email and company, so we can follow up if the AI gets stuck, and to prevent abuse.

Limited to 2 questions per hour and 5 per day, kept lean so the AI stays useful. For more, contacting us directly works better for you and us.

Or skip the DIY entirely

Our Managed IT clients do not look these things up. One point of contact, a fixed monthly price, resolved within working hours.