Domain Validation Digital Certificate (Server) with “Wildcard” feature

Domain Validation (DV) Digital Certificate (d-Cert) (Server) with “Wildcard” feature provides standard SSL/TLS encryption for a primary domain and all of its subdomains by verifying the applicant’s control over the base domain. This solution enables secure HTTPS connections across the entire website, removes “Not Secure” warnings displayed by web browsers, and delivers a basic level of data protection while enhancing user confidence.​

​The certificate utilises a wildcard character (the asterisk “*”) as the left‑most component of the fully qualified domain name. When issued, the certificate covers the specified domain and its subdomains without explicitly including the wildcard character in the server name. It supports deployment across server names at the same domain or subdomain level owned by the applicant organisation and is offered with a one‑year subscription period.​

During the one‑year subscription period, applicants are entitled to obtain an unlimited number of new d-Cert (Server) under the same application at no additional charge. The validity period of each newly issued certificate will be subject to either the phased maximum validity period or the remaining subscription period, whichever is shorter.​

Example​

A DV d-Cert (Server) with the “Wildcard” feature issued for *.hkca.hk may be used to secure all server names under the same domain hkca.hk, including but not limited to:​

  • www.hkca.hk
  • hkca.hk
  • mail.hkca.hk
  • www1.hkca.hk

Note:

  1. A DV d-Cert (Server) with the “Wildcard” feature is issued for use on one server by default.
  2. For installation on multiple servers, an additional subscription fee applies for each additional server. The number of additional servers must be specified at the time of application.​
  3. Each additional physical server or virtual machine operating on a separate operating system from the default server is considered a chargeable additional server.​
  4. Applicants may increase the number of additional servers at any time during the subscription period, provided that the applicable subscription fee per additional server, covering the entire subscription period of the certificate, is paid.​
  5. The certificate includes digital signature key usage, the Subject Alternative Name (SAN) field, and the Extended Key Usage field. For details, please refer to Appendix B of the Certification Practice Statement (CPS).​
  6. Digital signatures supported by the DV d-Cert (Server) with the “Wildcard” feature are intended solely for server authentication and the establishment of secure communication channels. They must not be used for contract negotiations, legally binding agreements, or monetary transactions.​

Eligibility for DV d-Cert (Server) with “Wildcard” Feature​

​A DV d-Cert (Server) with “Wildcard” feature is intended for individuals, organisations, and businesses that operate a website with multiple sub‑domains and require basic SSL/TLS encryption across their domain structure. It is suitable for website owners who need to confirm control over a base domain and secure the main domain and all its sub‑domains under a single certificate, without requiring verification of the organisation’s legal identity.​

​This certificate is commonly used for websites with multiple sub‑domains, such as portals, service platforms, or content sections, where foundational security and encryption are required across the entire site.​

Document required for the DV d-Cert (Server) application

  •  Copy of proof of ownership of all the applied domain name(s) to be included in the certificate

If the Applicant is a company registered in Hong Kong :

  • Copy of Business Registration Certificate issued by the Inland Revenue Department
  • Copy of Certificate of Incorporation / Certificate of Registration issued by the Companies Registry (applicable to limited companies)
  • Completed, signed and stamped Authorisation Letter designating the authorised representation

If the Applicant is a bureau or department of the HK SAR Government :

  • A memo signed by the Departmental Secretary (or staff at equivalent rank or above) and endorsed with department chop designating the Authorised Representative

If the Applicant is statutory body in Hong Kong :

  • Copy of the ordinance(s) under which the statutory body was established
  • Completed, signed and stamped Authorisation Letter.

 

​Benefits of Using a DV d-Cert (Server) with “Wildcard” Feature​

The use of a DV d-Cert (Server) with “Wildcard” feature enables website owners to encrypt data transmitted between users and servers using standard SSL/TLS technology while securing one primary domain and all of its sub‑domains under a single certificate. It supports HTTPS connections, removes “Not Secure” warnings in common web browsers, and provides a consistent level of data confidentiality and integrity across the website.​

​In addition, a Wildcard DV d-Cert (Server) simplifies certificate management, reduces the need for multiple certificates for individual sub‑domains, and provides an efficient and cost‑effective solution for securing websites where high‑assurance organisational identity verification is not required.

Click here to log in d-Cert Subscriber Portal to register or submit d-Cert (Server) application.