# CERTIFICATE\_DOMAIN\_MISMATCH when using wildcard certificate

**URL:** <https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544>\
**Category:** Beta 6.0\
**Created:** [November 26, 2023, 6:38pm UTC](https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544 "2023-11-26T18:38:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christian\_S](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/c/f05b48/32.png) [@Christian\_S](https://discourse.pi-hole.net/u/Christian_S)\
**Post date:** [November 26, 2023, 6:38pm UTC](https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544/1 "2023-11-26T18:38:40Z")

</div>

Hi,

I'm using pihole as plain setup with a wildcard certificate.

pihole throws a error message that the wildcard (\*.domain.tld) does not match the domain (subdomain.domain.tld)

> SSL/TLS certificate /etc/nginx/ssl/domain.tld does not match domain **pi.domain.tld**!

---

<div class="post-metadata">

**Author:** ![DL6ER](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dl6er/32/281_2.png) [@DL6ER](https://discourse.pi-hole.net/u/DL6ER)\
**Post date:** [November 26, 2023, 9:28pm UTC](https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544/2 "2023-11-26T21:28:26Z")

</div>

Ah yes, I guess nobody had thought about wildcard certificates when implementing this change. Thank you for your very concise bug report!

Could you please try

```auto
pihole checkout ftl fix/wildcard_crt_check

```

and see if this fixes the problem? You can also use the CLI tool to test this more easily by running

```auto
pihole-FTL --read-x509 "/etc/nginx/ssl/domain.tld" "pi.domain.tld"

```

and seeing if it says there is a match (or not). You can also run

```auto
pihole-FTL --read-x509 "/etc/nginx/ssl/domain.tld"

```

without a domain to see how Pi-hole parses your certificate file.

* * *

[https://github.com/pi-hole/FTL/pull/1782](https://github.com/pi-hole/FTL/pull/1782)

---

<div class="post-metadata">

**Author:** ![deHakkelaar](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/dehakkelaar/32/674_2.png) [@deHakkelaar](https://discourse.pi-hole.net/u/deHakkelaar)\
**Post date:** [November 28, 2023, 10:31pm UTC](https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544/3 "2023-11-28T22:31:21Z")

</div>

> [@Christian\_S](#):
>
> wildcard certificate

Wildcard certs are not recommended from a security point of view:

> Con:  
> The biggest concern with wildcard certificates is that when one server or sub-domain covered by the wildcard is compromised, all sub-domains may be compromised. In other words, the upfront simplicity of the wildcard can create significant problems should things go wrong.

> **[What are the pros and cons of a wildcard certificate?](https://knowledge.digicert.com/quovadis/ssl-certificates/ssl-general-topics/what-are-the-pros-and-cons-of-a-wildcard-certificate)**
>
> Wildcard certificates can secure an unlimited number of subdomains within a domain name. However, there are some drawbacks you need to consider.

I've also read about attacks involving wildcard certs.

Safer to create a SAN cert (Subject Alternative Name) containing all the domains you want to secure!  
If use **certbot** :

```auto
$ man certbot
[..]
   -d DOMAIN, --domains DOMAIN, --domain DOMAIN
       Domain names to apply. For multiple domains you can
       use multiple -d flags or enter a comma separated list
       of domains as a parameter. The first domain provided
       will be the subject CN of the certificate, and all
       domains will be Subject Alternative Names on the
       certificate. The first domain will also be used in
       some software user interfaces and as the file paths
       for the certificate and related material unless
       otherwise specified or you already have a certificate
       with the same name. In the case of a name collision it
       will append a number like 0001 to the file path name.
       (default: Ask)

```

EDIT:

```auto
$ openssl s_client -connect chess.com:443 -servername www.chess.com </dev/null 2>/dev/null | openssl x509 -noout -text | grep 'Subject:.* CN =\|Alternative Name\|DNS:'
        Subject: CN = chess.com
            X509v3 Subject Alternative Name:
                DNS:blog.chess.com, DNS:chess.com, DNS:chesskid.com, DNS:chesskids.com, DNS:chesspark.com, DNS:merch.chess.com, DNS:pogchamps.chess.com, DNS:shop.chess.com, DNS:shop.chesskid.com, DNS:www.chesskids.com, DNS:www.chesspark.com

```

---

<div class="post-metadata">

**Author:** ![halhalhal](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/h/9de053/32.png) [@halhalhal](https://discourse.pi-hole.net/u/halhalhal)\
**Post date:** [March 9, 2025, 7:11pm UTC](https://discourse.pi-hole.net/t/certificate-domain-mismatch-when-using-wildcard-certificate/66544/4 "2025-03-09T19:11:45Z")

</div>

my wildcard certificate works now without warning after update from pi.hole 6.0.2 to 6.0.4. Thank you.
