security/nss/lib/mozpkix/lib/pkixnames.cpp
Likewise for Chromium:
trunk/src/net/base/x509_certificate.cc
(I've intentionally not linked these because burdening the relatively heavyweight source viewers with idle HN readers who are mostly going to glaze over and not read once they discover it's tricky C++ code seems unfair)
My guess would be that because it's harder to process multiple wildcards at all, and indeed even the sketchy single wildcard in odd position (which Symantec used to issue and argued wasn't technically prohibited e.g. dev-*.auditcompany.example where auditcompany.example was a domain belonging to Symantec's auditors...) it's less likely anybody goes to the effort to do this even though it's a bad idea.
But I guess if the wrong programmer is assigned the problem they might cheerfully write a nice loop to process wildcards even though it's more effort and the wrong thing so we can't rule out that it has happened somewhere at least once.
I'd say that statement seems a bit unfair and glad someone else linked to a source below.
Seems like a good use case for linking to their respective GitHub mirrors
https://github.com/chromium/chromium/blob/master/net/cert/x5...
https://github.com/mozilla/gecko-dev/blob/master/security/ns...
*.*.example.com
and foo.*.example.com
aren't allowed.Not sure what the current state of software accepting these things is, but minimally, CAs are not allowed to issue anything like that.