
Is 118 DNS SANs, Many Being Wildcards, in One Certificate Bad Practice or Just a Thing?
CertificatesDNSWildcardsCybersecurity
The user examined the certificate for www.bayareafastrak.org before paying a toll and was surprised to find that it was issued for imperva.com with 118 SANs, 62 of which are wildcards. Among these SANs are *.dol.gov and *.cims.ukhsa.gov.uk. The user assumes that imperva is doing hosting but finds it dubious to reuse the same certificate for multiple tenants when an SNI configuration would allow one certificate per tenant.