A wildcard certificate does not cover the root domain #194
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
A wildcard certificate is not valid for the root domain.
The certificate
*.example.comis NOT valid for the domainexample.comIt would only be valid if contained an additional SAN to cover the root domain.
According to the this RFC, a wildcard certificate does not cover the root domain.
https://datatracker.ietf.org/doc/html/rfc6125#section-6.4.3
Where te last line describes the problem "*.example.com would match foo.example.com but not bar.foo.example.com or example.com"
The tests have been updated where the certificate that is being used contains a SAN for
*.otherdomain.com. The subdomainswww.otherdomain.comandanother.otherdomain.comare valid, but the root domainotherdomain.comnot.