[Hosting] Use free wildcard SSL certificate from Cloudflare

We migrated our subdomain-based multisite to WPMU DEV hosting and found out that it doesn’t come with a wildcard SSL certificate. We want to use the free wildcard SSL certificate that Cloudflare provides.

We asked the Live Support team if it will work with WPMU DEV hosting, but they claimed that the Cloudflare wildcard SSL certificate won’t work because “They are private self-signed certificates meant to be used for the connection between ‘Cloudflare and the webserver’. Origin CA certificates only encrypt traffic between Cloudflare and your origin web server and are not trusted by client browsers when directly accessing your origin website outside of Cloudflare.”

But we believe they’re not. Here are some articles we found that say different:
https://howarddc.com/free-ssl-certificate-cloudflare/
https://www.fixrunner.com/how-to-setup-cloudflare-ssl-on-wordpress/

Could you please clarify?

  • Predrag Dubajic
    • Support

    Hi Jepser ,

    As you can see in the first link that you shared it also mentions that the host will need to have at least self-signed SSL certificate in order for that setup to work.
    At the moment we don’t support wildcard SSL and up until now we required the wildcard certificate to be sent to us so our sysadmins could apply it to site in question.

    I said “up until now” because we’re working on adding wildcard SSL cert option to our hosting so the certificate will be automatically created and renewed even for subdomain installations.

    Our devs are actively working on this and we’re hoping to have this functionality added anytime soon.

    In the meantime, you can add your subdomains in the Domains tab and that will create an SSL certificate for each subdomain added there, and it can be used as a temporary solution (without paying for wildcard SSL) until the wilcard SSL functionality is released.

    Best regards,
    Predrag