SSL Certificates: Multiple Single Domain vs Wildcard

internetSecuritysslssl-certificate

I'm my company we want to deploy SSL certificates to some websites we own, and our RADIUS server as well (Cisco ACS).

What is the practical difference from acquiring 5-10 single host certificates or a single wildcard certificate for the whole domain (ie: common to all the hosts) ?

All hosts are in the same domain. I'm not sure what certificate to choose.

Thanks,

Best Answer

I just asked a similar queston. I belive part of the trade off is cost and security. If one cert is compromised thats just one out of 5-10 but you are paying more per cert. If you have one cert it is less but if it gets compromised you are looking at 10 points of failure now.

From another site:

SSL Wildcard Certificates won't work for multiple levels. This means that an SSL Certificate Wildcard for *.mydomain.com won't work on www.mail.mydomain.com

I'd encourage you to read http://www.sslshopper.com/best-ssl-wildcard-certificate.html for a pro/con on Wildcard certs.