If I purchase a signed certificate for example.com, can I then produce sub-certificates for a.example.com and b.example.com?
These sub-certificates would have PEM files whose privacy cannot be assured.
Can I do this, maintaining the privacy of the root certificate while generating an unlimited number of disposable sub-certificates that would still be recognized as valid by the original signing authority?