Sectigo® CaaS DV + Wildcard + Multi Domain Information

Sectigo® CaaS DV + Wildcard + Multi Domain is a multi-domain and wildcard SSL Certificate delivered through Trustico® Certificate as a Service (CaaS). It secures a primary domain, additional names held as Subject Alternative Names (SANs), and wildcard names that cover every subdomain at a chosen level, all on one SSL Certificate.

The SSL Certificate is issued and reissued automatically through the Automatic Certificate Management Environment (ACME) protocol, which pairs the trust of a long-established Certificate Authority (CA) with programmatic management. Coverage runs from a few names to hundreds, and a wildcard entry such as *.example.com secures unlimited subdomains beneath it.

It suits a business running several websites alongside subdomain-heavy platforms, where named sites and whole subdomain trees are provisioned and retired through automation rather than by hand.

Secures Multiple Domain Names 🔗 Secures Unlimited Subdomains 🔗
USD $500,000 Relying Party Warranty 🔗 Instant Domain Control Validation 🔗
Programmatic Management Includes Hosted Issuance Tool 🔗
Includes Sectigo® Site Seal 🔗 2048-bit Industry Standard SSL Certificate
Optional Installation Service 🔗 Unlimited Reissue Policy 🔗
99.9% Web Browser Ubiquity 🔗 Unlimited Server Licenses

The sections below explain what the SSL Certificate covers, how the automation works, and how to put it in place.

Sectigo® Trust Across Your Names

Sectigo® is a long-established, widely trusted commercial Certificate Authority (CA), with root Certificates present in virtually every browser, operating system, and device. Every named site and every subdomain on your SSL Certificate inherits that trust.

This matters when you present several brands, regional sites, and subdomain services to the public, since each name is trusted without any configuration on the visitor's device. Learn About the Sectigo® Certificate Authority (CA) 🔗

Named Sites and Subdomains on One Automated SSL Certificate

This SSL Certificate combines two kinds of coverage on one SSL Certificate. Separate names are held as Subject Alternative Names (SANs), which can be different domains such as example.com, example.net, and another-brand.com, along with individual subdomains.

A wildcard entry such as *.example.com then secures every subdomain directly beneath that domain, including ones you create later, and the root domain is included. Coverage of named sites runs from a few names to hundreds. Explore Multi Domain Coverage 🔗

Each wildcard label position is covered by its own wildcard entry, so you can include a wildcard for more than one domain when your platform needs it. Understand Wildcard Coverage 🔗

The Case for Certificate as a Service (CaaS) with Many Names

Managing an SSL Certificate that spans several domains and whole subdomain trees by hand grows awkward as the list changes. Each time it nears expiry, someone generates a Certificate Signing Request (CSR), completes validation for every name, downloads the files, and installs them on each server. Certificate as a Service (CaaS) automates all of that.

Note : Where no Automatic Certificate Management Environment (ACME) client can be run, the same SSL Certificate can be issued from your Certificate as a Service (CaaS) license in a browser through Domain Name System (DNS) validation. Explore the Hosted Issuance Tool 🔗

When you order Sectigo® CaaS DV + Wildcard + Multi Domain, you are buying an SSL Certificate license for a set period. Through that period your ACME client reissues the SSL Certificate as it approaches expiry, so every name and subdomain stays protected for the term.

When the license nears its end, you can extend it without reinstalling or reconfiguring anything across your servers. The extended validity is recognized automatically, with no change to your External Account Binding (EAB) credentials or your automation. Learn About License Extensions 🔗

Validation with ACME

Sectigo® CaaS DV + Wildcard + Multi Domain uses the Automatic Certificate Management Environment (ACME) protocol, defined in RFC 8555, to run the SSL Certificate lifecycle. An ACME client on your server handles verification, issuance, installation, and reissue for every name on the SSL Certificate.

Domain Validation (DV) confirms control of each name, with no organization checks, so the SSL Certificate issues quickly once every name is confirmed. Each name is validated on its own, and names on different servers can be confirmed independently.

For a named site, the client answers a challenge by serving a token over HTTP or by publishing a Domain Name System (DNS) TXT record. A wildcard entry is always validated through Domain Name System (DNS), because the Certificate Authority (CA) must confirm control of the base domain rather than a single server.

Because a wildcard uses Domain Name System (DNS) validation, your ACME client needs to support a Domain Name System (DNS) challenge, which most complete through provider integrations such as Cloudflare, AWS Route 53, and DigitalOcean. Explore ACME Protocol Details 🔗

Supported ACME Clients

Any major Automatic Certificate Management Environment (ACME) client that supports Domain Name System (DNS) validation works with Sectigo® CaaS DV + Wildcard + Multi Domain. Certbot is the most widely used and covers wildcards through its Domain Name System (DNS) plugins. acme.sh suits scripted, scheduled reissue with a wide range of provider integrations.

For Kubernetes, cert-manager issues and reissues the SSL Certificate as a native cluster resource. Windows environments are covered by win-acme and Certify The Web for Microsoft Internet Information Services (IIS), while lego, dehydrated, and Posh-ACME cover Go, shell, and PowerShell setups.

Whichever client you choose, it authenticates with the Certificate Authority (CA) through the same External Account Binding (EAB) process and validates each name before the SSL Certificate is issued. Find Out More About Supported ACME Clients 🔗

Tip : If your sites run on cPanel, the Trustico® Certificate as a Service (CaaS) cPanel plugin brings automated SSL Certificate management into your hosting control panel, without the command line. It performs the Domain Name System (DNS) validation a wildcard needs, provided that zone is managed on the same cPanel server. Explore the Trustico® cPanel Plugin 🔗

On cPanel hosting the plugin fills the role of the ACME client, requesting and reissuing the SSL Certificate for the names and subdomains you manage on that server.

External Account Binding Credentials

External Account Binding (EAB) links your ACME client to the Certificate Authority (CA). Trustico® creates a Key Identifier and an HMAC Key and sends them to you via e-mail after purchase, and they are also available in your ordering account for a limited time. You provide them when you first set up the client to authorize it.

You can generate separate External Account Binding (EAB) credentials for different servers or environments, which helps where the same group of names is managed by more than one client across production, staging, and development. View Our EAB Credential Setup Guide 🔗

Encryption and Protocols

Protection is built on a 2048-bit RSA key with 256-bit symmetric encryption, applied consistently to every name and subdomain, over the Transport Layer Security (TLS) 1.2 and 1.3 protocols with SHA-256 hashing.

Certificate Transparency logging adds accountability, and Elliptic Curve Cryptography (ECC) keys are supported for environments that benefit from smaller keys and faster handshakes. Compare Encryption Standards 🔗

Preparing for Shorter Validity Periods

Industry rules are reducing the maximum validity of an individual SSL Certificate to 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029. These reductions apply to every publicly trusted Certificate Authority (CA), Sectigo® included.

At a 47 day cycle, an SSL Certificate covering many names and subdomains across several servers would need reissuing roughly eight times a year. With Certificate as a Service (CaaS), your ACME client handles each reissue quietly, so everything stays protected whatever the validity period. Explore Traditional and Certificate as a Service (CaaS) Compared 🔗

USD $500,000 Warranty

Every Sectigo® CaaS DV + Wildcard + Multi Domain SSL Certificate carries a USD $500,000 Relying Party Warranty covering the secured names and subdomains, which provides financial cover in the unlikely event that the Certificate Authority (CA) issues the SSL Certificate in error. Reissues are unlimited across the license through the automation. Review Warranty Details 🔗

Sectigo® Site Seal

Your order includes a Sectigo® site seal that you can display across your secured sites to reassure visitors. The Sectigo® name on the seal is one that visitors and businesses already recognize. Implement Trust Seals 🔗

Browser Compatibility

Because the Sectigo® roots are in virtually every trust store, each secured name and subdomain is trusted by around 99.9% of web browsers, including Chrome, Firefox, Safari, and Edge, and by mobile devices on iOS and Android without any additional configuration. Understand Browser Compatibility 🔗

Unlimited Server Licenses

You can install the SSL Certificate on as many servers as you need at no extra cost. This matters when your names and subdomains run on separate infrastructure, across web servers, application servers, load balancers, and container nodes.

The same SSL Certificate and key file are deployed to each server that serves a secured name, and where a server needs its own key you can reissue as often as required through the automation.

Programmatic Installation

The ACME client installs the SSL Certificate for you, generating the Certificate Signing Request (CSR), completing validation for each name, and deploying the issued files. Documentation covers Apache, Nginx, Microsoft Internet Information Services (IIS), cloud platforms, and container systems. Access Installation Guides 🔗

Guides and Resources

Trustico® provides guides covering ACME client setup, Domain Name System (DNS) validation, External Account Binding (EAB) credentials, and combined wildcard and multi-domain deployment. For reissue scheduling specific to your client, refer also to that client's own documentation. Browse Technical Resources 🔗

Who Should Use Sectigo® CaaS DV + Wildcard + Multi Domain

It fits a business that runs several websites alongside subdomain-heavy platforms, provisioned through infrastructure as code with tools such as Terraform, Ansible, and CloudFormation.

It also suits agencies and hosting providers securing many client domains and their subdomains under a single automated SSL Certificate, and SaaS platforms that assign customer subdomains such as client.yourdomain.com. Learn About the Partner Service 🔗

Other Options

If you only need wildcard coverage of subdomains without additional named sites, the wildcard option secures a domain and everything beneath it. Compare Sectigo® CaaS DV + Wildcard 🔗

For the full range of automated SSL Certificates across single site, wildcard, and multi-domain coverage, explore the service overview. Explore Certificate as a Service (CaaS) 🔗

Certificate as a Service (CaaS) - Pricing

Trustico® Certificate as a Service (CaaS) provides automated SSL Certificate issuance through the Automated Certificate Management Environment (ACME) protocol. The table below shows the price for each Certificate as a Service (CaaS) product.

Product Name Supplier List Price Your Price
Trustico® CaaS DV Single Site 🔗
$155.00 AUD
$88.00 AUD Save 43%
Trustico® CaaS DV + Wildcard 🔗
$775.00 AUD
$349.00 AUD Save 55%
Sectigo® CaaS DV Single Site 🔗
$141.00 AUD
$102.00 AUD Save 28%
Sectigo® CaaS DV + Wildcard 🔗
$704.00 AUD
$408.00 AUD Save 42%

Sectigo® CaaS DV Single Site vs Wildcard Comparison

Certificate as a Service (CaaS) provides automated SSL Certificate management through APIs. Choose Single Site for individual domain automation, or Wildcard for comprehensive subdomain coverage with full API-driven SSL Certificate lifecycle management.

Feature Sectigo® CaaS DV Single Site Sectigo® CaaS DV + Wildcard
Service Type Certificate as a Service (CaaS) Certificate as a Service (CaaS)
Coverage Single Domain Only Unlimited Subdomains
Domains Covered www.example.com + example.com *.example.com + example.com
Automation Level Fully Automated Fully Automated
API Access Full RESTful API Full RESTful API
Validation Level Domain Validation (DV) Domain Validation (DV)
Validation Methods E-Mail / DNS / HTTP / HTTPS E-Mail / DNS / HTTP / HTTPS
Issuance Time Very Fast! Issued Within Minutes Very Fast! Issued Within Minutes
Auto-Renewal Automated Renewal Available Automated Renewal Available
Certificate Management Centralized Dashboard Centralized Dashboard
Integration Options API, Webhooks, SDK API, Webhooks, SDK
Ideal For SaaS Platforms, Single Domain Apps Multi-Tenant SaaS, Complex Infrastructures
Scalability Per-Domain Scaling Automatic Subdomain Coverage
Warranty $500,000 USD $500,000 USD
Encryption Strength 256-bit SSL Encryption 256-bit SSL Encryption
Browser Compatibility 99.9% Browser Trust 99.9% Browser Trust
Dual Domain Coverage Includes Root Domain SAN Free! Includes Root Domain SAN Free!
Reissues Unlimited Unlimited
Deployment Options Cloud, On-Premise, Hybrid Cloud, On-Premise, Hybrid
Information Page Product Information Page 🔗 Product Information Page 🔗
Your Trustico® Price $102.00 AUD $408.00 AUD
Purchase Options Instant - Buy Now 🔗 Instant - Buy Now 🔗

Most Popular Questions

Frequently asked questions covering Sectigo® CaaS DV + Wildcard + Multi Domain, a combined multi-domain and wildcard SSL Certificate delivered through Certificate as a Service (CaaS), including what it covers, the license and reissue model, how named sites and wildcard entries are validated, supported ACME clients, and the included warranty.

Coverage of Sectigo® CaaS DV + Wildcard + Multi Domain

Sectigo® CaaS DV + Wildcard + Multi Domain secures a primary domain, additional names held as Subject Alternative Names (SANs), and wildcard names that cover every subdomain at a chosen level, all on one SSL Certificate. Coverage of named sites runs from a few names to hundreds, and a wildcard entry such as *.example.com secures unlimited subdomains beneath it. It is issued and reissued automatically through the Automatic Certificate Management Environment (ACME) protocol.

Combining Named Sites and Wildcard Subdomains

Separate names are held as Subject Alternative Names (SANs), which can be different domains as well as individual subdomains. A wildcard entry such as *.example.com then secures every subdomain directly beneath that domain, and the root domain is included. Each wildcard label position is covered by its own wildcard entry, so more than one domain can carry a wildcard.

The SSL Certificate License Model

When you order Sectigo® CaaS DV + Wildcard + Multi Domain, you are buying an SSL Certificate license for a set period. Through that period your Automatic Certificate Management Environment (ACME) client reissues the SSL Certificate as it approaches expiry, extending the expiry date against the validity remaining on your license. You order once and every name and subdomain stays protected for the term.

Validating Named Sites and Wildcard Entries

A named site is validated by the Automatic Certificate Management Environment (ACME) client serving a token over HTTP or publishing a Domain Name System (DNS) TXT record. A wildcard entry is always validated through Domain Name System (DNS), because the Certificate Authority (CA) must confirm control of the base domain rather than a single server. Domain Validation (DV) applies no organization checks, so issuance is quick once every name is confirmed.

Deploying Across Multiple Servers

Sectigo® CaaS DV + Wildcard + Multi Domain includes unlimited server licensing, so you can install the same SSL Certificate across web servers, application servers, load balancers, and container nodes at the same time. Each server that serves a secured name or subdomain carries the same issued SSL Certificate. Where a server needs its own key file, you can reissue as often as required through the automation.

Shorter Validity Periods and Automation

Industry rules are reducing the maximum validity of an individual SSL Certificate to 200 days from March 2026, 100 days from March 2027, and 47 days from March 2029, which applies to every publicly trusted Certificate Authority (CA), Sectigo® included. At a 47 day cycle an SSL Certificate covering many names and subdomains would need reissuing roughly eight times a year. Certificate as a Service (CaaS) handles each reissue within your license period without manual effort.

Supported ACME Clients for Combined Deployment

Any major Automatic Certificate Management Environment (ACME) client that supports Domain Name System (DNS) validation works with Sectigo® CaaS DV + Wildcard + Multi Domain, including Certbot, acme.sh, cert-manager for Kubernetes, and win-acme or Certify The Web on Windows. Each client authenticates with the Certificate Authority (CA) through External Account Binding (EAB) and validates every name before the SSL Certificate is issued. A client that supports a Domain Name System (DNS) challenge is required because of the wildcard entries.

Warranty for Sectigo® CaaS DV + Wildcard + Multi Domain

Every Sectigo® CaaS DV + Wildcard + Multi Domain SSL Certificate carries a USD $500,000 Relying Party Warranty covering the secured names and subdomains, which provides financial cover in the unlikely event that the Certificate Authority (CA) issues the SSL Certificate in error. The SSL Certificate also includes the Sectigo® site seal, unlimited reissues through the automation, and unlimited server licensing.