GlobalSign AlphaSSL Wildcard
The GlobalSign AlphaSSL Wildcard certificate is a Domain Validated (DV) certificate that secures a domain along with an unlimited number of first-level subdomains under a single purchase, so mail., shop., and blog. subdomains are all covered without buying separate certificates for each. It's issued under GlobalSign's root and validates domain control only, so it goes live within minutes of DNS or file verification rather than waiting on business document checks. It carries the same 2048-bit RSA encryption and SHA-256 signing as the standard single-domain option, with the added flexibility of adding new subdomains later without reissuing or repurchasing.
The GlobalSign AlphaSSL Wildcard certificate is a Domain Validated (DV) SSL product issued under GlobalSign's root, covering a domain plus an unlimited number of first-level subdomains under one purchase. It verifies domain control only, without checking company registration or legal identity. It suits site owners who need SSL for subdomains — mail, staging, shop, or blog — consolidated under a single certificate rather than purchased separately for each one. Because validation stops at domain control, the certificate can be issued, and later reissued to add servers, without submitting any business paperwork at any stage.
What Does GlobalSign AlphaSSL Wildcard Cover?
A GlobalSign AlphaSSL Wildcard certificate secures the root domain named on it and every first-level subdomain beneath it, so mail.example.com, shop.example.com, and blog.example.com are all covered by one purchase — the main practical difference from the standard AlphaSSL certificate, which covers only the single domain specified at order. This also means new subdomains created after the certificate is issued are covered automatically, with no need to reissue or repurchase when a project adds a new subdomain later. Coverage has clear limits:
- A second-level subdomain such as test.shop.example.com falls outside the wildcard scope and needs its own certificate;
- Unrelated domains are not covered under the same certificate;
- No organisation or company name is displayed in the browser, since DV validation confirms domain control only.
Who Needs GlobalSign AlphaSSL Wildcard?
This certificate fits domains running several services on subdomains, including:
- A company site with a separate webmail portal;
- A SaaS product with a customer-facing app on one subdomain and a staging environment on another;
- An agency managing client subdomains under one root domain;
- A blog with a shop subdomain added later;
- A development team running multiple test or demo environments on subdomains of one project domain.
It is not the right fit for a single standalone domain with no subdomains, where a standard single-domain certificate is cheaper and covers the same need, or for a site requiring visible company verification, which calls for an OV or EV certificate instead.
Key Features of GlobalSign AlphaSSL Wildcard
The certificate is defined by a fixed set of technical specifications:
- Validation type: DV only, confirmed via DNS record, HTTP file, or email to a domain-listed address.
- Encryption: 2048-bit RSA keys, SHA-256 signature algorithm.
- Issuance: typically within minutes after DNS or file validation clears.
- Coverage: root domain plus unlimited first-level subdomains, one level deep only.
- Reissue: unlimited during the validity period, at no extra charge.
- Warranty: included, amount fixed by GlobalSign's certificate terms.
- Browser support: recognised across all current major browsers, no client-side root installation required.
Validity is typically sold in one-year terms in line with current industry-standard maximum certificate lifespans, and renewal needs to be completed before expiry to avoid a gap in encryption across every subdomain the certificate covers, not just the root domain.
How to Get GlobalSign AlphaSSL Wildcard: 3 Steps
Issuance runs through three steps from request to installation:
- Generate a CSR (Certificate Signing Request) for the root domain with an asterisk prefix (e.g. *.example.com).
- Submit the CSR and complete DNS, file, or email validation to confirm control of the root domain.
- Download the certificate and intermediate files once GlobalSign issues them, and install them on each server or subdomain that needs coverage.
To buy GlobalSign AlphaSSL Wildcard, select the Wildcard option in the order form rather than the single-domain listing. It sits in the DV category alongside other DV GlobalSign AlphaSSL Wildcard products, so it's worth comparing validity periods and reissue terms before confirming the order. Where subdomains are hosted on different servers, the same certificate and private key (or a reissued version matching each server's own CSR) can be installed on each one, so a single purchase can cover infrastructure split across several machines rather than one physical or virtual server.