Hacker News new | past | comments | ask | show | jobs | submit login

This is definitely true, and single-domain or SAN certificates should continue to be the first option administrators consider when deploying TLS. Wildcards make sense for things where the number of subdomains is unmanageable and where each of those subdomains share the same attack vector (i.e. are handled by the same load balancer, etc.)

The fact that validation for wildcard certificates is limited to the DNS challenge will hopefully ensure that most users will continue to use non-wildcards, as the other challenges are significantly easier to automate.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: