RFC 6125 - Representation and Verification of Domain-Based Application Service Identity within Internet Public Key Infrastructure Using X.509 (PKIX) Certificates in the Context of Transport Layer Security (TLS):
'via Blog this'
Some dislike wildcard certificates.
Me: I want wildcard signing certificates. E.g. I want to be able to sign certificates for anything under https://*.andy.glew.ca