About this interactive
A standard certificate is issued for one name. techknowsurge.com's main site and its courses site are different names, so even on the same server they need two different certificates. The owner submits a CSR for each, proves they own the domain, and gets each certificate from a certificate authority.
A wildcard certificate has an asterisk at the start of its name: *.techknowsurge.com. One certificate then covers www.techknowsurge.com, courses.techknowsurge.com and other names in the domain. The catch is the private key. There is one public key in the certificate, so every server using it holds the same private key. If one of those servers is compromised and the key leaks, every service has to get new keys and a new certificate. And if a site is hosted by someone else, you would not hand them that private key; you would get a separate certificate for that site instead.
A self-signed certificate is generated on the device itself, with no CSR, no domain check and no certificate authority. It still encrypts the traffic, which is often all an admin wants when connecting to a switch. But it verifies nobody, so browsers show a warning, and the only way through is to accept the risk. That is fine for an admin team who know exactly which device they are connecting to. It is dangerous for end users, because it trains them to click past security warnings, which they will then do on sites that really are fake.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →