I have a reverse proxy that is in front of all my services (caddy) which uses a wildcard cert to avoid this very concern.
anyways, what i liked about caddy was how easily it handles SSL-certs, for sure makes it easier to use! :) gonna have to look into how i can give a wildcard-cert to my rev-proxy.