Multi-domain & wildcards
Issue one certificate for several domains by passing an array to for(), or append SANs fluently with alsoFor(). Wildcards are supported — on the acme driver only over DNS-01:
// requires a DnsChallengeSolver in drivers.acme.solver
Certificates::for(['app.example.com', '*.app.example.com'])->using('acme')->issue();
Certificates::for('example.com')
->alsoFor('www.example.com', 'api.example.com')
->using('acme')
->issue();The first domain is the primary: it is stored on the domain column and drives the derived certificate name. When more than one domain is requested, the full list is stored on the additive domains JSON column.
Finding the covering certificate
The coveringDomain scope matches rows whose primary domain equals the host or whose SAN list contains it:
use RoundlyConsulting\Certificates\Models\Certificate;
$certificate = Certificate::query()->coveringDomain('www.example.com')->first();
$certificate->domain; // 'example.com' — the primary domain
$certificate->domains; // ['example.com', 'www.example.com', 'api.example.com']Driver support
Drivers that implement ProvisionsMultipleDomains — acme, filesystem, kubernetes and array — receive the full list in one generateMany() call: one ACME order, one self-signed certificate or one Ingress TLS entry. Others (null, or a custom driver without the interface) fall back to the primary domain. Every domain is lowercased, de-duplicated and validated with ValidDomain first; *. wildcards pass by default. A renewal re-provisions every domain the certificate covers, so a SAN certificate keeps all its hosts.
CAs, Let’s Encrypt included, never offer HTTP-01 for a *. name, so register a DNS-01 solver first — see ACME & Let’s Encrypt. With the default HTTP-01 solver a wildcard order fails with an AcmeException that says so.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.