SSL Certificate Examples · Example 4 of 4 in Certificate Problems
A Certificate for Another Host Name
A certificate for another host name: valid is false with "Hostname mismatch" for wrong.host.badssl.com.
Asks for the certificate of wrong.host.badssl.com.
The certificate is a valid Let's Encrypt certificate for *.badssl.com and badssl.com, but a wildcard covers only one label, so it does not cover wrong.host.badssl.com. signature.valid is false and invalid_reason reads Hostname mismatch, certificate is not valid for 'wrong.host.badssl.com'..