Assuming this will be done with your own PKI, and not a public trusted CA.
Considering that *.sub.domain.com
is valid, and so is *.domain.com
is valid, is it technically possible to issue *.com
and even a *.
certificate?
The certificate I'm investigating is a "*." certificate being used for any other domain name such as "https://google.com" and then performing MITM attacks.
Will any certificate validation framework support a *.
certificate? Will it be rejected outright, or will normal validation rules apply?