> Are wildcard certficates good? secure? useful?

There's a problem with wildcard certs wrt how URLs are being displayed in 
many of the browsers, esp. the older ones. If the host name is extremely 
long the browser will be unable to show the complete URL to the user, 
with some browsers even inserting "..." into the address window.   

Now, suppose I buy a certificate for * (assuming that I'm 
the owner of that domain). I could then set up an SSL server with a 
hostname of something like

hoping that the browser will only display the more familiar looking parts 
of the URL to the user who in turn will happily accept the certificate.  

You get the idea.


