Subdomains having separate SSL certificates

Hi,

I have multiple subdomains registered with my domain (all in Cloudflare) and I only want a single wildcard SSL/TLS certificate for my domains (to prevent subdomain enumeration from SSL/TLS certificate registration logs - e.g. which can be seen from sites like crt.sh).

Most of my subdomains are plain Cloudflare Pages projects and some to other external projects.
  • I have the CNAMEs set to proxy (maybe that's the issue?)
  • I have SSL/TLS set to "Full (strict)" for the domain
  • In my Edge Certificate section, I have have only two certificates (a universal and a backup, both targeting my domain and my domain with a subdomain wildcard)
Is there a way to tell Cloudflare to not register certificates for every subdomain and rather use the universal wildcard certificate?

Thank you so much!
Was this page helpful?