Wildcard certificates below the internal name of a computer ("*.member5.intranet.mydomain.com) should be possible. The idea is that a host "requests the certificate", the DC Master creates it, the host downloads it. +++ This bug was initially created as a clone of Bug #45115 +++ We should think about making the app available via appid.domain (not only fqdn/app)