How to issue a wildcard SSL certificate
Let this node serve your DNS zone and TNS Panel issues one Let's Encrypt certificate for *.example.com and example.com through DNS-01.
When the DNS zone for a domain is served by this node, the panel validates the certificate against the node's own BIND with DNS-01 and issues a single wildcard certificate: *.example.com plus example.com. It then covers the site and every subdomain you add later, without spending more of the shared Let's Encrypt quota.
Steps
- Create the site for
example.com(how). - Under DNS, create the zone for
example.comon this node, then set your registrar's name servers to the node's name servers. - Wait until the domain resolves to this node.
- Open the site's certificate page and request the certificate, or wait for the scheduler. The panel adds the validation TXT record to your zone itself and removes it afterwards.
- Check the certificate page shows both
example.comand*.example.com.
If the zone is not served here
Each name then gets a normal certificate over HTTP-01, so the domain must already point at the node and be reachable on port 80. A wildcard cannot be issued in that case.
Good to know
- A wildcard does not cover the bare domain on its own; that is why the certificate lists both names.
- Issuing on demand is rate-limited per domain, to protect the shared Let's Encrypt quota. If it refuses, wait and try again.
- Parked domains and subdomains use the site's wildcard and never request a certificate of their own.
FAQ
My wildcard failed. Does the site have no certificate?
The panel falls back to a certificate with the exact names, so the site is not left without HTTPS.
Last updated: 2026-10-10