What Is a Multi-Domain SSL SAN Certificate and Who Needs It

什么是多域SSL证书?

多域SSL证书——也称为SAN证书(主题备选名称)或UCC(统一通信证书)——是一个单一的SSL证书,可同时保护多个不同的域名。您无需为每个域名购买和管理单独的证书,而是使用一个证书来覆盖所有域名。

例如,如果您经营具有多个品牌或网站的业务,单个多域SSL可以覆盖:

与其使用五个单独的SSL证书,您只管理一个。这大大降低了成本和管理开销。

SAN、多域和UCC——它们有区别吗?

这些术语在很大程度上描述相同的技术,但其起源不同:

SAN证书如何覆盖多个域

多域SSL的核心是证书内的一个称为主题备选名称(SAN)的字段。当浏览器打开HTTPS网站时,服务器返回其证书,浏览器检查地址栏中输入的域名是否与证书中列出的名称之一匹配。从历史上看,证书是根据仅保存单个域的通用名称(CN)字段进行验证的。现代标准改为针对SAN字段进行验证——SAN可以在单个证书中保持许多域的列表。

该过程大致如下:

  1. 创建列出每个域的CSR——生成证书签名请求(CSR)时,您指定要覆盖的每个域。主域进入CN,其余部分添加到SAN列表。
  2. 证明每个域的所有权——证书颁发机构(CA)针对SAN列表中的每个名称运行域控制验证,而不仅仅是主域。这通常通过DNS记录、网站上的文件或电子邮件质询进行验证。
  3. CA颁发包含每个SAN的一个证书——验证所有域后,CA颁发单个证书,其SAN字段列出所有域。
  4. 在服务器上安装——此单一证书安装在服务器上,并立即保护其列出的每个域。

结果是,无论访客打开mybrand.com还是anotherbrand.com,浏览器都会在SAN列表中看到该名称,并正常显示挂锁和加密连接,没有安全警告——全部来自同一个证书。

多域SSL vs 通配符SSL:有什么区别?

这是关于SSL类型最常见的问题之一。两者都覆盖多个域或名称,但工作方式不同:

通配符SSL(*.domain.com)

多域SSL(SAN)

简单规则:如果您拥有asiagb.com和injan.co.th作为单独的域,请使用多域SSL。如果您只有asiagb.com但需要覆盖许多子域,如shop.asiagb.com、api.asiagb.com、blog.asiagb.com,请改用通配符SSL。

Single vs Multi-Domain (SAN) vs Wildcard Compared

The table below summarizes the differences between the three main SSL types, so you can pick the one that matches your own site structure:

Aspect Single Domain Multi-Domain (SAN) Wildcard
Coverage One domain only, e.g. mybrand.com Multiple different domains, e.g. brandA.com, brandB.co.th One domain + all its subdomains, e.g. *.mybrand.com
Subdomains Only those listed (usually incl. www) Yes, but each must be listed by name All one-level subdomains automatically
Multiple TLDs No Yes (.com .co.th .net in one cert) No (bound to one domain)
Best for A single site on one domain Multiple brands / domains / TLDs Sites with many subdomains under one domain
Starting price (AsiaGB) DV from 1,000 THB/year DV + extra cost per added SAN Wildcard from 5,000 THB/year

In short: if you have one domain with many subdomains, Wildcard is the most cost-efficient. If you have several unrelated domains or TLDs, Multi-Domain (SAN) is the answer. And if you truly run a single site, a Single Domain SSL from 1,000 THB/year is enough.

Who Should Use Multi-Domain SSL? (Multiple Brands / TLDs)

Multi-Domain SSL is especially well suited to organizations managing several domain names at once — particularly when those domains sit on different TLDs or represent different brands. Groups that benefit most include:

1. Businesses with Multiple Brands or Domains

Companies operating under multiple brand names, each with its own domain, can consolidate SSL management. This is common in holding companies, agencies, or businesses that operate the same product in multiple markets under different domain names.

2. E-commerce with Multiple Storefronts

Online retailers who maintain separate domains for different product categories or regional markets — for example, myshop.com and myshopthailand.co.th — can secure both with a single certificate, simplifying management and reducing cost.

3. Microsoft Exchange and Office 365 Environments

Exchange Server deployments require securing multiple service names on the same server — such as mail.company.com, autodiscover.company.com, and owa.company.com. UCC Certificates are the industry standard for these deployments and are supported natively by Exchange.

4. Agencies and IT Teams Managing Multiple Clients

Web agencies or IT departments managing websites for multiple organizations can consolidate certificate management across client domains, reducing renewal overhead and potentially lowering per-domain costs.

5. One Brand Registered Across Many TLDs to Prevent Brand Squatting

Many businesses register the same brand name across several extensions — for example mybrand.com, mybrand.co.th, mybrand.net, and mybrand.asia — to stop others from grabbing their brand. Even if some of these domains simply redirect to the main one, every domain that answers over HTTPS still needs a valid SSL certificate, or browsers will show a warning. A Multi-Domain SSL handles this entire scenario in a single certificate, so you don't have to buy and renew a separate certificate for each TLD.

Issuing and Installing a SAN Certificate: What to Know

Before ordering and installing a Multi-Domain SSL, there are technical details worth understanding so the process goes smoothly and you avoid unnecessary reissues:

Plan Your Full Domain List Up Front

Because adding or removing a domain later requires a reissue every time, list all the domains and subdomains you expect to use this year before generating the CSR. Many SAN cert plans include a minimum number of SAN slots (e.g. 3-5 names) and let you buy additional SANs individually. Planning ahead lets you purchase exactly the right number of SAN slots.

Every Domain Must Pass Domain Control Validation

The CA validates ownership of every domain in the SAN list, not just the primary one. If some domains aren't fully set up in DNS yet, or you can't access their admin email, issuance will stall until all of them are verified. So make sure you have DNS or web-root control over every domain before placing the order.

Install One Certificate Across All Relevant Servers

If all your domains live on the same server, installing the certificate and its CA bundle (intermediate) once covers every domain. If your domains are spread across multiple servers, you can install the same certificate and private key on each server — just keep the private key secure and transfer it only over encrypted channels.

Understand Reissues and the Shared Expiry Date

Every domain in the certificate shares the same expiry date. When you renew or add a domain, the system issues an entirely new certificate that you must install over the old one on every server. Keep a record of exactly where this certificate is installed, so that at renewal time no server is missed and you don't end up with an expired SSL somewhere.

Pros and Cons of Multi-Domain SSL

Advantages

Disadvantages

Multi-Domain SSL from AsiaGB

AsiaGB offers SSL Certificates from RapidSSL, GeoTrust, and DigiCert — all leading Certificate Authorities with full Multi-Domain SSL product lines at DV, OV, and EV validation levels. SSL starts from 1,000 THB/year. If you are unsure whether Multi-Domain or Wildcard SSL is right for your situation, contact the AsiaGB team for a recommendation.

Frequently Asked Questions (FAQ)

How many domains can a Multi-Domain SSL cover?

It depends on the plan and CA. A SAN cert typically comes with a starting number of domains (e.g. 3-5 names) and lets you add SANs one at a time up to that plan's maximum (some plans support dozens or even over a hundred domains). Tell the team how many domains you need so you can pick a plan with the right number of SAN slots at the best value.

Does Multi-Domain SSL also cover subdomains of each domain?

It only covers the subdomains you explicitly list as SAN entries — for example, you must list shop.brandA.com by name for it to be covered. If you want to automatically cover all subdomains of a given domain, consider a Wildcard, or choose a SAN cert that supports Wildcard SAN entries (adding *.brandA.com as one of the SANs), which some CAs offer.

Can I add a domain to the certificate later?

Yes, but it requires a reissue — the CA issues a new certificate containing the added domain, which you then install over the old one on every server. The expiry date stays the same; reissuing doesn't extend it. Planning your full domain list at purchase time avoids this hassle.

Is Multi-Domain SSL really cheaper than buying certificates individually?

It is clearly cheaper once you have three or more domains, because the per-domain price of a SAN cert is lower than buying separate certificates, and it's easier to manage with one expiry date and one renewal. But if your "domains" are really many subdomains under a single root domain, a Wildcard SSL from 5,000 THB/year is usually the better deal.

Interested in Multi-Domain SSL for Your Business?

SSL Certificates from RapidSSL, GeoTrust, DigiCert starting from 1,000 THB/year.

View SSL Certificates