Skip to main content
banner image
venafi logo

Education Center - What is a Wildcard Certificate?

What is a Wildcard Certificate?

A wildcard certificate is a public key certificate (like SSL/TLS) that can be used on multiple subdomains, usually purchased from a trusted public certificate authority.

So, for example, if I had a wildcard certificate for then I could possibly cover:

I could use one wildcard certificate, whether it was SSL or TLS, and use it to secure my website for all of these subdomains. Without a wildcard certificate, I would need one certificate for each of these subdomains in order to secure them all. In the case above I would have to buy 4 individual certificates and each one would be set to secure each of the 4 subdomains.

With a wildcard certificate purchase, you can usually also cover your "naked domain." This would mean that I could add in addition to the 4 subdomains that my wildcard certificate already covers and now cover a 5th subdomain without any additional cost.

Wildcard certificates are typically used to cover all domains with the same registered root making it simple to administer. However, the flexibility that comes with utilizing wildcard certificates also creates significant security risks since the same private key is used across multiple systems, thereby increasing the risk of compromise across the organization:

  • Compromised web server—using a wildcard certificate on public-facing webservers increases the risk that cybercriminals will use the webserver to host malicious sites for phishing campaigns.
  • Stolen private key— gaining access to a wildcard certificate’s private key provides attackers with the ability to impersonate any domain for the wildcard certificate.
  • Fake certificates—cybercriminals can trick a CA into issuing a wildcard certificate for a fictitious company. Once a hacker has the fictitious company’s wildcard certificates, the attacker can create subdomains and establish phishing sites.

Without proper security, control, and monitoring of wildcard certificates, they can be easily misused by cybercriminals to exploit the trust organizations have in wildcard certificates and use them in phishing attacks.

If you are looking to find out where your wildcard certificates are installed, trial Venafi as a Service for free today.


Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

Subscribe Now

get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon
Venafi Risk assessment Form Image

Sign up for Venafi Cloud

Venafi Cloud manages and protects certificates

* Please fill in this field Please enter valid email address
* Please fill in this field Password must be
At least 8 characters long
At least one digit
At last one lowercase letter
At least one uppercase letter
At least one special character
* Please fill in this field
* Please fill in this field
* Please fill in this field

End User License Agreement needs to be viewed and accepted

Already have an account? Login Here

get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more