Sectigo PositiveSSL Wildcard
- Covers *.example.com plus apex
- Unlimited subdomains
- Issued in minutes after DV
- $50,000 warranty
- Free unlimited reissues
A wildcard certificate for *.example.com covers www, mail, shop, api and any subdomain you create later. No reissues when the site grows, no per-host bookkeeping.
Prices are the full cost for the chosen term. Longer terms lower the average yearly price.
Pick a billing period
No products match your filter.
Prices without VAT; Latvian VAT is 21% where it applies. Prices follow the certificate authorities daily.
From 24 February 2026 a public SSL certificate is issued for up to 199 days, so the file is shorter lived than before. It is a security win: short-lived certificates are much harder to abuse if a key ever leaks. Your multi-year price here does not change and there is no extra cost. At each interval you reissue the certificate yourself in the client panel, which shows how many days are left.
*.example.com matches one label: every direct subdomain, no matter how many you add.
www.example.com, mail.example.com, shop.example.com and the apex example.com itself on most brands.
staging.example.com spun up next year is covered the moment DNS resolves. No reissue, no new order.
Deeper levels like a.b.example.com need a wildcard for *.b.example.com or a SAN entry.
Generate the CSR with *.example.com as the common name, or let us prepare it for you.
One DV check for the whole domain by DNS record or email; OV brands add company vetting.
Install the same bundle on every server and service that hosts a subdomain.
New CA/Browser Forum rules cut the maximum validity of a public SSL certificate step by step, down to just 47 days by 2029.
A 47-day certificate means 8 or more renewals every year, so automation becomes the only practical way to stay secure. On our multi-year plans the price never changes. Today you reissue the certificate yourself in the client panel at each interval; if you want it hands-off, our ACME certificate renews automatically.
Yes. On the brands we sell the certificate includes both *.example.com and example.com, so the apex domain is secured without extra entries or a second certificate. In practice that means a visitor who types example.com without any subdomain still gets a valid HTTPS connection from the same certificate that protects www, mail or shop. You do not have to configure anything special: the apex entry is part of the issued certificate itself, and you can verify it in the browser after issuance. If you want to confirm coverage for a specific brand before ordering, write to support and we will check it for you.
As many as you need. Install the same certificate and private key on every web, mail or API server that serves a subdomain; licensing is unlimited and there is no extra cost per server. This matters when one domain is spread across several machines, for example a website on one server and mail on another: they can all present the same wildcard. Keep the private key protected on each machine, and remember that every copy must be replaced when the certificate is renewed, so it is worth keeping a simple list of everywhere it is installed.
No. The asterisk in *.example.com matches exactly one label, so shop.example.com or api.example.com are covered, but a.b.example.com is not, because it sits one level deeper. To secure that name you need a separate wildcard for *.b.example.com or a multi-domain certificate with the exact hostname added as a SAN entry. In practice it pays to plan your naming early: if everything lives directly under the main domain, one wildcard is enough, while deep structures multiply certificates. If you are unsure which layout fits your case, write to support and describe the hostnames you plan to use.
No. No certificate authority issues EV wildcards, because CA/B Forum rules do not allow extended validation to be combined with a wildcard name. The strongest validation available for a wildcard is OV, for example GeoTrust TrueBusinessID or DigiCert Wildcard SSL, where the CA vets the company behind the domain and includes it in the certificate. For most sites this is sufficient: encryption strength is the same across validation levels, the difference is how thoroughly the owner is checked. If a policy in your organization strictly requires EV, it can only be applied to certificates that list exact hostnames rather than an asterisk.
Choose a wildcard when everything sits under one domain: it covers an unlimited number of subdomains of example.com, including ones you create later. Choose a SAN, or multi-domain, certificate when several different domains need to share one certificate, for example a company running separate sites on different names. The two approaches can be combined: multi-domain certificates can carry wildcard SAN entries, so one certificate covers several domains and all their subdomains at once. A practical way to decide is to list every hostname you serve today and expect to add. If the list keeps growing under a single domain, wildcard wins; if you are unsure, send the list to support and we will suggest the simplest option.
At CloudHosting wildcard SSL starts at 80.67 EUR a year for Sectigo PositiveSSL Wildcard, a DV certificate that fits most sites. RapidSSL costs more, and OV brands such as GeoTrust and DigiCert are priced higher still, because the CA also vets the company behind the domain. All prices are shown without VAT; Latvian VAT of 21% applies where relevant. The amount on the page is the full cost for the chosen term, and picking a longer term lowers the average yearly price. Brands differ in validation depth and warranty level, so paying more mainly makes sense when your customers expect a vetted company name in the certificate.
DV wildcards such as PositiveSSL and RapidSSL are issued within minutes once domain validation is completed, and there is only one check for the whole domain: you either add a DNS record or confirm a link sent to an email address on that domain. The real waiting time is usually on your side, for example waiting for a DNS change to propagate. OV brands like GeoTrust TrueBusinessID and DigiCert additionally vet the company behind the order, a step that cannot be fully automated, so issuance takes noticeably longer; order OV certificates ahead of any deadline. If validation gets stuck, write to support and we will help you through it.
Start by counting the hostnames you actually serve. If the answer is one, for example www.example.com, a single-domain certificate is enough and there is no reason to pay for more. As soon as you run mail, shop, api or staging alongside the main site, separate certificates mean separate orders, separate validations and separate renewal dates to track. One wildcard from 80.67 EUR a year replaces all of that with a single certificate and a single renewal, and any subdomain you add later is covered automatically. It is usually cheaper than several individual certificates, and always simpler to administer.
Deploy in minutes or talk to an engineer about what fits your project.