Web Hosting Talk







View Full Version : WildCard SSL question


Jedito
08-23-2002, 02:35 PM
I'm thinking in get a wildcard SSL certificate, but I have a problem :)

When I generate the .crt which "Common name" should I use?

domain.com?
*.domain.com?

Or what must I use?

probe
08-23-2002, 04:06 PM
From Thawte:
The domain name entered here will be the "common name" used for the
certificate. Clients will verify that the system to which they connected
matches this domain name, so you'll want to ensure that you choose the
appropriate name for the server. For example, if a system is really named
frodo.domain.com, but people will be accessing it as mail.domain.com, the
domain name chosen here should be mail.domain.com

Some Certificate Authorities (such as Thawte) will permit a "wildcard"
domain name here, i.e., *.domain.com. If you have several hostnames within
a particular domain that you will be supporting, this may be a better
choice, but you'll need to ensure that the Certificate Authority that
you'll be using to sign your certificate will support this form for the
certificate's common name. Unfortunately, not all clients will recognize
wildcard characters in the domain name, and those clients will be
presented with a warning that the certificate's domain name doesn't match
the server's domain name. The current versions of both Microsoft's and
Netscape's clients, however, do support wildcarded domain names.

Domain name of TLS/SSL server for which request is being
generated: *.domain.com