Sectigo® CaaS DV + Wildcard Information

Sectigo® CaaS Domain Validation (DV) + Wildcard is a Wildcard SSL Certificate delivered through Trustico® Certificate as a Service (CaaS). It secures every subdomain directly under your domain, at *.yourdomain.com, along with the root domain yourdomain.com.

The SSL Certificate is issued and reissued automatically through the Automatic Certificate Management Environment (ACME) protocol, which pairs the trust of a long-established Certificate Authority (CA) with programmatic management. One order covers unlimited subdomains at that level, including ones you add later.

It suits organizations running changing subdomain infrastructure, teams scaling environments through automation, and anyone who wants full programmatic control of a Wildcard SSL Certificate from a widely recognized Certificate Authority (CA).

Secures Unlimited Subdomains + Root Domain 🔗 Instant Domain Control Validation 🔗
USD $500,000 Relying Party Warranty 🔗 2048-bit Industry Standard SSL Certificate
Programmatic Management Delivered Via E-Mail
Includes Sectigo® Site Seal 🔗 Unlimited Server Licenses
Optional Installation Service 🔗 Unlimited Reissue Policy 🔗
99.9% Web Browser Ubiquity 🔗 Extend the License Without Reinstallation

The sections below explain what the SSL Certificate covers, how the automation works, and how to put it in place.

Sectigo® Trust Across Your Subdomains

Sectigo® is a long-established, widely trusted commercial Certificate Authority (CA), with root Certificates present in virtually every browser, operating system, and device. Every subdomain secured under *.yourdomain.com inherits that trust, so visitors reach app.yourdomain.com, portal.yourdomain.com, or any other subdomain over a trusted connection.

This matters where you serve customers, partners, or internal teams across many subdomains, since each one is recognized without any trust store configuration. Learn About the Sectigo® Certificate Authority 🔗

Full Wildcard Subdomain Coverage

A single *.yourdomain.com entry secures every subdomain directly beneath yourdomain.com, such as app.yourdomain.com, staging.yourdomain.com, and api.yourdomain.com, and the root domain yourdomain.com is included as well. There is no need to hold a separate SSL Certificate for each subdomain.

Coverage applies to the subdomains you have now and to any you create later at that level. When you launch a new service on a fresh subdomain, it is protected straight away, which suits environments where subdomains appear as part of deployment or onboarding. Understand Wildcard Coverage 🔗

The Case for Certificate as a Service (CaaS) with Wildcards

Managing a Wildcard SSL Certificate by hand gets harder as your subdomains grow. Each time it nears expiry, someone must generate a Certificate Signing Request (CSR), complete validation, download the files, and install them on every server that serves your subdomains. Certificate as a Service (CaaS) automates all of that.

When you order Sectigo® CaaS Domain Validation + Wildcard, you are buying an SSL Certificate license for a set period. Throughout that period your ACME client reissues the Wildcard SSL Certificate as it approaches expiry, extending the expiry date against the validity remaining on your license. You order once and every subdomain stays protected for the term.

When the license period nears its end, you can extend it without any reinstallation or reconfiguration across your servers. The extended validity is recognized automatically, and there is no need to update your External Account Binding (EAB) credentials or change your automation. Learn About License Extensions 🔗

Wildcard Automation with ACME

Sectigo® CaaS Domain Validation + Wildcard uses the Automatic Certificate Management Environment (ACME) protocol, defined in RFC 8555, to run the SSL Certificate lifecycle. An ACME client on your server handles verification, issuance, installation, and reissue, and it authenticates with the Certificate Authority (CA) using External Account Binding (EAB) credentials from your Trustico® account.

A Wildcard SSL Certificate is validated through Domain Name System (DNS) validation, because the Certificate Authority (CA) must confirm control of the base domain rather than a single server.

The client creates a temporary Domain Name System (DNS) TXT record, and many clients automate this through integrations with the major Domain Name System (DNS) providers, including Cloudflare, AWS Route 53, and DigitalOcean.

Because this method does not need your web server to be publicly reachable, it also works for subdomains behind a firewall or on internal networks. Once the Certificate Authority (CA) confirms control, the SSL Certificate is issued, and every later reissue runs the same way. Explore ACME Protocol Details 🔗

Supported ACME Clients for Wildcard Deployment

Any major ACME client that supports Domain Name System (DNS) validation works with Sectigo® CaaS Domain Validation + Wildcard. Certbot is the most widely used and supports wildcards through its Domain Name System (DNS) plugins. acme.sh offers a wide range of Domain Name System (DNS) provider integrations and suits scripted, scheduled reissue.

For Kubernetes, cert-manager issues and reissues wildcards as a native cluster resource. Windows environments are covered by win-acme and Certify The Web for Microsoft Internet Information Services (IIS), while lego, dehydrated, and Posh-ACME cover Go, shell, and PowerShell setups.

Whichever client you choose, it authenticates with the Certificate Authority (CA) through the same External Account Binding (EAB) process and completes Domain Name System (DNS) validation to receive your Wildcard SSL Certificate. Find Out More About Supported ACME Clients 🔗

Tip : If your website runs on cPanel, the Trustico® Certificate as a Service (CaaS) cPanel Plugin brings automated SSL Certificate management directly into your hosting control panel, without the command line. It retrieves, installs, and reissues your SSL Certificates from within cPanel itself. Explore the Trustico® cPanel Plugin 🔗

On cPanel hosting, the plugin fills the role of the ACME client and performs the Domain Name System (DNS) validation a wildcard needs, provided that zone is managed on the same cPanel server.

External Account Binding Credentials

External Account Binding (EAB) links your ACME client to the Certificate Authority (CA). You generate a Key Identifier and an HMAC Key in your Trustico® account and provide them when you first set up the client. This one-time step authorizes the client to request and reissue your Wildcard SSL Certificate.

You can generate separate External Account Binding (EAB) credentials for different servers or environments, which is useful where the same *.yourdomain.com SSL Certificate is managed by more than one client across production, staging, and development. View Our EAB Credential Setup Guide 🔗

Encryption and Protocols

Sectigo® CaaS Domain Validation + Wildcard uses a 2048-bit RSA key with 256-bit symmetric encryption applied consistently to every subdomain, over the Transport Layer Security (TLS) 1.2 and 1.3 protocols with SHA-256 hashing.

Certificate Transparency logging adds accountability, and Elliptic Curve Cryptography (ECC) keys are supported for environments that benefit from smaller keys and faster handshakes. Compare Encryption Standards 🔗

Preparing for Shorter Validity Periods

Industry rules are reducing the maximum validity of an individual SSL Certificate to 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029. These reductions apply to every publicly trusted Certificate Authority (CA), Sectigo® included.

At a 47 day cycle a Wildcard SSL Certificate that protects many subdomains across several servers would need reissuing roughly eight times a year. With Certificate as a Service (CaaS), your ACME client handles each reissue quietly, so your subdomains stay protected whatever the validity period. Explore Traditional and CaaS Compared 🔗

USD $500,000 Warranty

Every Sectigo® CaaS Domain Validation + Wildcard SSL Certificate carries a USD $500,000 Relying Party Warranty covering the secured subdomains, which provides financial cover in the unlikely event that the Certificate Authority (CA) issues the SSL Certificate in error. Reissues are unlimited across the license through the automation. Review Warranty Details 🔗

Sectigo® Site Seal

Your order includes a Sectigo® site seal that you can display across your subdomains to reassure visitors. The Sectigo® name on the seal is one that visitors and businesses already recognize. Implement Trust Seals 🔗

Browser Compatibility

Because the Sectigo® roots are in virtually every trust store, every subdomain is trusted by around 99.9% of web browsers, including Chrome, Firefox, Safari, and Edge, and by mobile devices on iOS and Android without any additional configuration. Understand Browser Compatibility 🔗

Unlimited Server Licenses

You can install the Wildcard SSL Certificate on as many servers as you need at no extra cost. This matters for cloud-native setups where the same *.yourdomain.com SSL Certificate must be present on every node that serves your subdomains, across web servers, application servers, load balancers, and containers.

Programmatic Installation

The ACME client installs the Wildcard SSL Certificate for you by generating the Certificate Signing Request (CSR), completing Domain Name System (DNS) validation, and deploying it. Documentation covers integration for Apache, Nginx, Microsoft Internet Information Services (IIS), cloud platforms, and container systems. Access Installation Guides 🔗

Guides and Resources

Trustico® provides guides covering ACME client setup, Domain Name System (DNS) validation, External Account Binding (EAB) credentials, and wildcard deployment. For plugin configuration and reissue scheduling specific to your client, refer also to that client's own documentation. Browse Technical Resources 🔗

Who Should Use Sectigo® CaaS Domain Validation + Wildcard

It fits teams that need wildcards from a widely recognized Certificate Authority (CA) for compliance or policy reasons, provisioned through infrastructure as code with tools such as Terraform, Ansible, and CloudFormation, and organizations running containerized applications across Kubernetes clusters that create subdomains dynamically.

It also suits SaaS platforms that assign customer subdomains such as client.yourdomain.com, hosting providers managing many subdomains under a shared domain, and continuous integration pipelines that spin up feature-branch environments needing coverage the moment they are created.

Other Options

If you do not need programmatic automation and would rather manage a Wildcard SSL Certificate by hand, the standard Domain Validation wildcard option covers the same names. Compare Domain Validation Wildcard 🔗

Certificate as a Service (CaaS) - Pricing

Trustico® Certificate as a Service (CaaS) provides automated SSL Certificate issuance through the Automated Certificate Management Environment (ACME) protocol. The table below shows the price for each Certificate as a Service (CaaS) product.

Product Name Supplier List Price Your Price
Trustico® CaaS DV Single Site 🔗
-
602,00 NOK
Trustico® CaaS DV + Wildcard 🔗
-
2.407,00 NOK
Sectigo® CaaS DV Single Site 🔗
-
704,00 NOK
Sectigo® CaaS DV + Wildcard 🔗
-
2.815,00 NOK

Sectigo® CaaS DV Single Site vs Wildcard Comparison

Certificate as a Service (CaaS) provides automated SSL Certificate management through APIs. Choose Single Site for individual domain automation, or Wildcard for comprehensive subdomain coverage with full API-driven SSL Certificate lifecycle management.

Feature Sectigo® CaaS DV Single Site Sectigo® CaaS DV + Wildcard
Service Type Certificate as a Service (CaaS) Certificate as a Service (CaaS)
Coverage Single Domain Only Unlimited Subdomains
Domains Covered www.example.com + example.com *.example.com + example.com
Automation Level Fully Automated Fully Automated
API Access Full RESTful API Full RESTful API
Validation Level Domain Validation (DV) Domain Validation (DV)
Validation Methods E-Mail / DNS / HTTP / HTTPS E-Mail / DNS / HTTP / HTTPS
Issuance Time Very Fast! Issued Within Minutes Very Fast! Issued Within Minutes
Auto-Renewal Automated Renewal Available Automated Renewal Available
Certificate Management Centralized Dashboard Centralized Dashboard
Integration Options API, Webhooks, SDK API, Webhooks, SDK
Ideal For SaaS Platforms, Single Domain Apps Multi-Tenant SaaS, Complex Infrastructures
Scalability Per-Domain Scaling Automatic Subdomain Coverage
Warranty $500,000 USD $500,000 USD
Encryption Strength 256-bit SSL Encryption 256-bit SSL Encryption
Browser Compatibility 99.9% Browser Trust 99.9% Browser Trust
Dual Domain Coverage Includes Root Domain SAN Free! Includes Root Domain SAN Free!
Reissues Unlimited Unlimited
Deployment Options Cloud, On-Premise, Hybrid Cloud, On-Premise, Hybrid
Information Page Product Information Page 🔗 Product Information Page 🔗
Your Trustico® Price 704,00 NOK 2.815,00 NOK
Purchase Options Instant - Buy Now 🔗 Instant - Buy Now 🔗

Most Popular Questions

Frequently asked questions covering Sectigo® CaaS DV + Wildcard, a Wildcard SSL Certificate from Sectigo® delivered through Certificate as a Service, including what it covers, the license and reissue model, why wildcards use Domain Name System validation, supported ACME clients, and the included warranty.

Coverage of Sectigo® CaaS DV + Wildcard

Sectigo® CaaS DV + Wildcard secures every subdomain directly under your domain, at *.yourdomain.com, and the root domain yourdomain.com as well. Coverage applies to the subdomains you have now and to any you add later at that level. It is issued and reissued automatically through the Automatic Certificate Management Environment (ACME) protocol.

The SSL Certificate License Model for Wildcard

When you order Sectigo® CaaS DV + Wildcard, you are buying an SSL Certificate license for a set period. Throughout that period your ACME client reissues the Wildcard SSL Certificate as it approaches expiry, extending the expiry date against the validity remaining on your license. You order once and every subdomain stays protected for the term.

Extending the Wildcard License Without Reinstallation

When the license period nears its end, you can extend it without any reinstallation or reconfiguration across your servers. The extended validity is recognized automatically, and your ACME client keeps obtaining Wildcard SSL Certificates as usual. There is no need to update your External Account Binding (EAB) credentials or change your automation.

Domain Name System Validation for Wildcard SSL Certificates

A Wildcard SSL Certificate is validated through Domain Name System (DNS) validation, because the Certificate Authority (CA) must confirm control of the base domain rather than a single server. Your ACME client creates a temporary Domain Name System (DNS) TXT record, which the Certificate Authority (CA) checks before issuing. This method also works for servers behind a firewall, since it does not need the web server to be publicly reachable.

Supported ACME Clients for Wildcard Deployment

Any major ACME client that supports Domain Name System (DNS) validation works with Sectigo® CaaS DV + Wildcard. Certbot with Domain Name System (DNS) plugins is the most widely used, and acme.sh offers a wide range of provider integrations. Cert-manager handles wildcards natively in Kubernetes, while win-acme, Certify The Web, lego, dehydrated, and Posh-ACME cover Windows, Go, shell, and PowerShell setups.

Deploying the Wildcard SSL Certificate Across Multiple Servers

Sectigo® CaaS DV + Wildcard includes unlimited server licensing, so you can install the same Wildcard SSL Certificate across web servers, application servers, load balancers, and container nodes at the same time. This suits cloud-native setups where the same *.yourdomain.com SSL Certificate must be present on every node that serves your subdomains.

Shorter Validity Periods and Automation

Industry rules are reducing the maximum validity of an individual SSL Certificate to 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029, which applies to every publicly trusted Certificate Authority (CA) including Sectigo®. At a 47 day cycle a Wildcard SSL Certificate would need reissuing roughly eight times a year, and Certificate as a Service (CaaS) handles each reissue within your license period without manual effort.

Warranty for Sectigo® CaaS DV + Wildcard

Every Sectigo® CaaS DV + Wildcard SSL Certificate carries a USD $500,000 Relying Party Warranty covering the secured subdomains, which provides financial cover in the unlikely event that the Certificate Authority (CA) issues the SSL Certificate in error. The SSL Certificate also includes the Sectigo® site seal, unlimited reissues through the automation, and unlimited server licensing.