A
A
Alexander2018-08-30 17:10:07
Digital certificates
Alexander, 2018-08-30 17:10:07

Are there SSL certificates for 2 levels of subdomains at once?

We are going to start a lot of subdomains for the regional branches of the school.
there will be subdomains of the form:
kursk.school.ru
is.kursk.guitardo.ru
and in other regions. Just a few dozen pieces.
In reg.ru, they wrote to me that I would have to buy a separate certificate for each subdomain. And even if you take a Wildcard, on *.school.ru it will only protect subdomains one level deep. That is
, kursk.school.ru, sochi.school.ru,
and if you make is.kursk.school.ru subdomains, then you need to take a separate certificate for *.kursk.school.ru
Maybe there are certificates in nature, albeit much more expensive , but which act at least two levels deep?
That is, we buy one certificate for *.school.ru and protect all subdomains of all levels at once :-)
1. Does it exist in nature?
2. If not, how else can you optimize the protection of a large number of subdomains?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
B
bkosun, 2018-08-30
@bkosun

Wildcard SSL certificate for *.domain.com will be valid for sub.domain.com but not sub.sub.domain.com
This is done in accordance with RFC 2818:
https://tools.ietf.org/html/rfc2818#section -3.1
https://en.wikipedia.org/wiki/Wildcard_certificate
Use Multi-Domain (SAN) SSL:
https://www.digicert.com/multi-domain-ssl/
You can see how it works here:
https://www .sslshopper.com/ssl-checker.html#hostna...
You can also request a duplicate of an existing Wildcard certificate with alternative names.
https://www.digicert.com/ssl-support/wildcard-san-...

K
ky0, 2018-08-30
@ky0

Maybe there are certificates in nature, albeit much more expensive, but which act at least two levels deep?
That is, we buy one certificate for *.school.ru and protect all subdomains of all levels at once :-)

There are certificates that are much less expensive , which act on a specific domain (or subdomains), are easily and automatically issued / updated and, if properly configured, do not require almost any attention from a living person at all. And all these attempts to issue a Certificate of Omnipotence - IMHO, are rather sad from the point of view. security (many places of potential key compromise), cost optimization (we actually pay for air, if there is an alternative that is technically not inferior) and in 2018 they do not look very good.

C
CityCat4, 2018-08-30
@CityCat4

Get your CA - and do what you want. Plus it's free. Minus - requires brains, knowledge of what you are doing and installing a root certificate for each client.
IMHO, if you have money to buy school.ru - then probably there will be an admin who understands certificates. Although, of course, this is none of my business :)
You can, of course, try to add all the second levels to the SAN, but I have never done this, because at the corporate level, your CA is immeasurably simpler.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question