http://bugs.winehq.org/show_bug.cgi?id=22709
--- Comment #5 from Juan Lang juan_lang@yahoo.com 2010-05-19 20:24:03 --- Well, I'm full of bad information in this one: First, though it's off-topic for this bug, openssl does support the subject alternative name extension. (It doesn't support the name constraints extension, which is what I was thinking of when I piped up.) Second, RFC 1034 does describe wildcard RRs, so naturally the * is allowed in DNS names. I'd read somewhere that it wasn't, but I should have read the RFC more carefully.
I've got a patch series that demonstrates the problem that I'll send in. I may or may not have a chance to fix it before the code freeze.