A wildcard SSL cert for *.example.com from Let’s Encrypt
covers every one-level subdomain. You get one through the DNS-01 challenge, or, since February 2026, through the new DNS-PERSIST-01 challenge that skips per-renewal DNS edits. One wildcard cert replaces the per-service certs you’d otherwise juggle behind your reverse proxy.
Key Takeaways
- One wildcard cert covers every one-level subdomain under a domain, replacing dozens of per-service certs.
- Only DNS-based challenges (DNS-01 and DNS-PERSIST-01) issue wildcards; HTTP-01 and TLS-ALPN-01 won’t work.
- The newer DNS-PERSIST-01 challenge lets you authorize once and skip DNS edits on every renewal.
- Certbot and acme.sh both automate the DNS challenge through provider-specific plugins or tags.
- Systemd timers handle the 90-day renewal window cleanly, with deploy hooks to reload your reverse proxy.
Why Wildcard Certificates and When You Need Them
If you run three subdomains, single certs work fine. Each one gets its own HTTP-01 challenge, Certbot handles renewal, and life is simple. Once you pass 10 or 15 subdomains, the chore list grows. Every new service needs its own cert request, its own renewal entry, and its own way to break. A wildcard cert folds all of that into one.
Botmonster Tech




